Back to all
2026-09-29

Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)

ZUSOART ID
ZA-2026-13
CVE ID
CVE-2026-96440
Vulnerability Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)
CVSS 4.0 Base
7.1
Description

Improper  Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp  API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated  users to write files to arbitrary locations outside the intended upload  directory via the path parameter.

‍

Vendor
Flowring Technology Corp
Product
Category
Version affected
Agentflow 4.0
Before 2023/03/24
Mitigations

Update Agentflow 4.0 to 2023/03/24.

‍

Release date
2026-09-29
Credit

Jian You Chen (Jeremy Chen) of ZUSO ART

‍