SQL Injection Vulnerability in Flowise Product from Flowise Vendor
CVE-2025-29189
7.6HIGH
What is CVE-2025-29189?
The Flowise product, up to version 2.2.3, is susceptible to SQL Injection attacks through the tableName parameter in the Postgres_VectorStores module. This vulnerability can allow attackers to execute unauthorized SQL commands, potentially leading to data breaches and other malicious activities. It emphasizes the need for security measures to be implemented to protect sensitive information from exploitation.
