OSINT Graph Tool Vulnerability in Flowsint by Reconurge
CVE-2026-42156

7.1HIGH

Key Information:

Vendor

Reconurge

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-42156?

Flowsint, an open-source OSINT graph exploration tool for cybersecurity investigations, has a vulnerability that allows remote attackers to craft nodes with malicious types. This can lead to the escape of existing Cypher queries and enables adversaries to execute arbitrary Cypher queries. The issue has been addressed in version 1.2.3, and users are strongly encouraged to upgrade to mitigate this risk.

Affected Version(s)

flowsint < 1.2.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.