Remote File Exposure in Flowintel by Flowintel
CVE-2026-81659

7.1HIGH

Key Information:

Vendor

Flowintel

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81659?

Flowintel has a vulnerability that allows attackers to manipulate note content, which then gets processed by Pandoc and XeLaTeX during PDF export. This manipulation can lead to unauthorized access to local files on the Flowintel server, posing a significant security risk. Attackers can potentially retrieve sensitive information by exploiting this flaw. Users are advised to apply the latest patches to mitigate this risk.

Affected Version(s)

flowintel 0 <= 3.3.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
David Cruciani
.