Database Path Overwrite Vulnerability in Flowise by FlowiseAI
CVE-2026-69259

9.4CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-69259?

Flowise, a drag-and-drop interface for creating customized language models, has a vulnerability in the SQLite Record Manager node. This issue allows an authenticated attacker using the Docker image (running as root) to inject user-controlled configurations that may overwrite the SQLite database path. By manipulating the database setup, attackers could potentially write to sensitive paths like /etc/chromium/exploit.conf. This exploit could lead to the execution of arbitrary shell commands when Chromium is launched and configured with the crafted database file. The vulnerability has been addressed in version 3.1.3.

Affected Version(s)

Flowise < 3.1.3

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.