CVE-2026-69259
Last modified
CVE-2026-69259 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flowiseai | Flowise | < 3.1.3 |
References
- https://github.com/FlowiseAI/Flowise/pull/6464Issue Tracking, Patch
- https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3Patch, Release Notes, Vendor Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4mExploit, Vendor Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4mExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-69259?
How severe is CVE-2026-69259?
How do I fix CVE-2026-69259?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69253Flowise is a drag-and-drop user interface for building custo…8.8
- CVE-2026-69254Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-69255Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-69256Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-69257Flowise is a drag & drop user interface to build a customize…8.6
- CVE-2026-69258Flowise is a drag & drop user interface to build a customize…9.1
- CVE-2026-69262Flowise is a drag & drop user interface to build a customize…8.1
- CVE-2026-69263Flowise is a drag & drop user interface to build a customize…9.8
- CVE-2026-69264Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-co…9.8
- CVE-2026-69265Out-of-bounds read in Windows NTFS allows an authorized atta…7.8
- CVE-2026-69266Integer overflow or wraparound in Windows DHCP Server allows…8.8
- CVE-2026-69267Insufficient granularity of access control in Windows Connec…6.5
Are you affected by CVE-2026-69259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
