HIGH 8.7 NVD
CVE-2026-91934
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers t
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-pwfj-wh95-7mwp
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-via-sql-da
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.