Database Path Overwrite Vulnerability in Flowise by FlowiseAI
CVE-2026-69259
9.4CRITICAL
What is CVE-2026-69259?
Flowise, a drag-and-drop interface for creating customized language models, has a vulnerability in the SQLite Record Manager node. This issue allows an authenticated attacker using the Docker image (running as root) to inject user-controlled configurations that may overwrite the SQLite database path. By manipulating the database setup, attackers could potentially write to sensitive paths like /etc/chromium/exploit.conf. This exploit could lead to the execution of arbitrary shell commands when Chromium is launched and configured with the crafted database file. The vulnerability has been addressed in version 3.1.3.
Affected Version(s)
Flowise < 3.1.3
