SQL Injection Vulnerability in Flowise Product from Flowise Vendor
CVE-2025-29189

7.6HIGH

Key Information:

Vendor

Flowise

Status
Vendor
CVE Published:
9 April 2025

What is CVE-2025-29189?

The Flowise product, up to version 2.2.3, is susceptible to SQL Injection attacks through the tableName parameter in the Postgres_VectorStores module. This vulnerability can allow attackers to execute unauthorized SQL commands, potentially leading to data breaches and other malicious activities. It emphasizes the need for security measures to be implemented to protect sensitive information from exploitation.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.