CVE-2026-69259
Last modified
CVE-2026-69259 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path.
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FlowiseAI | Flowise | < 3.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-69259?
How severe is CVE-2026-69259?
How do I fix CVE-2026-69259?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69253Flowise is a drag-and-drop user interface for building custo…9
- CVE-2026-69254Flowise is a drag & drop user interface to build a customize…9.4
- CVE-2026-69255Flowise is a drag & drop user interface to build a customize…9.2
- CVE-2026-69256Flowise is a drag & drop user interface to build a customize…9.4
- CVE-2026-69257Flowise is a drag & drop user interface to build a customize…7.6
- CVE-2026-69258Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-69262Flowise is a drag & drop user interface to build a customize…7.1
- CVE-2026-69263Flowise is a drag & drop user interface to build a customize…8.7
- CVE-2026-69264Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-co…9.4
- CVE-2026-69278Incorrect authorization in Visual Studio Code allows an unau…7.8
- CVE-2026-6929The JoomSport – for Sports: Team & League, Football, Hockey …7.5
- CVE-2026-69306Not failing securely ('failing open') in Visual Studio Code …8.2
Are you affected by CVE-2026-69259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
