Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9c4c-g95m-c8cp | FlowiseDB vulnerable to SQL Injection by authenticated users |
Wed, 24 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including blind and error-based extraction of data from the credential table. | |
| Title | Flowise - SQL Injection in importChatflows API via chatflow.id Parameter | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-24T18:31:32.371Z
Reserved: 2026-06-20T01:48:36.755Z
Link: CVE-2025-71332
Updated: 2026-06-24T14:53:32.363Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T15:15:04Z
Github GHSA