CVE-2026-96440 Flowring Agentflow 路径遍历漏洞
影响认证用户可向任意路径写入文件,可能导致远程代码执行
Flowring Agentflow 4.0 的 /WebAgenda/download/uploadFile.jsp 接口存在路径遍历漏洞。攻击者通过操纵 path 参数,可将文件写入预期上传目录之外的任意位置。该漏洞需要远程认证用户权限。
影响范围
Flowring Agentflow 4.0 版本,2023/03/24 之前的版本受影响。
漏洞详情
漏洞类型为路径遍历(CWE-22),成因是 uploadFile.jsp 接口未对 path 参数进行充分的路径限制与过滤。攻击者可构造包含 ../ 等序列的路径,绕过上传目录限制,将恶意文件写入服务器任意位置。若写入 Web 可访问目录或系统关键路径,可能进一步导致远程代码执行。
利用条件与风险
利用前提是攻击者拥有有效的远程认证账户。实战中,拥有低权限账户的攻击者可借此上传 WebShell 或覆盖敏感文件,风险较高。
修复建议
建议升级至 2023/03/24 之后发布的修复版本。临时缓解措施包括限制上传接口的访问权限、对 path 参数进行严格白名单校验,暂无其他公开信息。
Improper Limitation of a Pathname to a Restricted
Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp
API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote
authenticated users to write files to arbitrary locations outside the intended
upload directory via the path parameter.