SQL Database Chain Vulnerability in Flowise Products by FlowiseAI
CVE-2026-91934

8.7HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91934?

Prior to version 3.1.4, Flowise fails to properly validate file paths in the SQL Database Chain node when interfacing with SQLite databases. This oversight permits authenticated attackers to exploit the system, enabling them to write arbitrary files to critical directories. They can effectively introduce malicious SQLite databases, jeopardizing the integrity of the system by executing commands or potentially carrying out stored XSS attacks.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alex-elttam
.