Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
| Software | From | Fixed in |
|---|---|---|
| flowring / agentflow | 4.0.0.1183.552 | 4.0.0.1183.552.x |