Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41274

Опубликовано: 23 апр. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. This vulnerability is fixed in 3.1.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Версия до 3.1.0 (исключая)

EPSS

Процентиль: 40%
0.00504
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-943

Связанные уязвимости

github
4 месяца назад

Flowise: Cypher Injection in GraphCypherQAChain

EPSS

Процентиль: 40%
0.00504
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-943