天下漏洞,尽知其名
HIGH

CVE-2026-96440 Flowring Agentflow 路径遍历漏洞

影响认证用户可向任意路径写入文件,可能导致远程代码执行

AI 研判

Flowring Agentflow 4.0 的 /WebAgenda/download/uploadFile.jsp 接口存在路径遍历漏洞。攻击者通过操纵 path 参数,可将文件写入预期上传目录之外的任意位置。该漏洞需要远程认证用户权限。

影响范围

Flowring Agentflow

Flowring Agentflow 4.0 版本,2023/03/24 之前的版本受影响。

漏洞详情

漏洞类型为路径遍历(CWE-22),成因是 uploadFile.jsp 接口未对 path 参数进行充分的路径限制与过滤。攻击者可构造包含 ../ 等序列的路径,绕过上传目录限制,将恶意文件写入服务器任意位置。若写入 Web 可访问目录或系统关键路径,可能进一步导致远程代码执行。

利用条件与风险

利用前提是攻击者拥有有效的远程认证账户。实战中,拥有低权限账户的攻击者可借此上传 WebShell 或覆盖敏感文件,风险较高。

修复建议

建议升级至 2023/03/24 之后发布的修复版本。临时缓解措施包括限制上传接口的访问权限、对 path 参数进行严格白名单校验,暂无其他公开信息。

原始情报

Improper Limitation of a Pathname to a Restricted
Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp
API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote
authenticated users to write files to arbitrary locations outside the intended
upload directory via the path parameter.