Input Injection Vulnerability in Flowise Drag & Drop Interface
CVE-2026-41274

9.3CRITICAL

Key Information:

Vendor

Flowiseai

Vendor
CVE Published:
23 April 2026

What is CVE-2026-41274?

Flowise, a drag & drop interface for building customized large language models, is affected by an input injection vulnerability in the GraphCypherQAChain node. This issue allows an attacker to supply unvalidated input directly into the Cypher query execution pipeline, leading to the execution of arbitrary Cypher commands on the underlying Neo4j database. The vulnerability can facilitate unauthorized data access, modifications, or deletions. It has been resolved in version 3.1.0.

Affected Version(s)

Flowise < 3.1.0

flowise-components < 3.1.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.