CVE-2026-69259: CWE-94: Improper Control of Generation of Code ('Code Injection') in FlowiseAI Flowise
CVE-2026-69259 is a critical code injection vulnerability in FlowiseAI Flowise prior to version 3.1.3. The SQLite Record Manager node improperly allows user-controlled configuration to overwrite the SQLite database path. An authenticated attacker using the official Docker image running as root could write malicious SQLite database files to arbitrary system paths, such as /etc/chromium/exploit.conf. By controlling table names and namespace values, the attacker could inject shell syntax that executes when Puppeteer launches Chromium and sources configuration files from /etc/chromium/*.conf. This vulnerability is fixed in version 3.1.3.
AI Analysis
Technical Summary
FlowiseAI Flowise versions before 3.1.3 contain a code injection vulnerability (CWE-94) in the SQLite Record Manager node. The node accepts an additionalConfig parameter that can overwrite the intended database path, allowing an attacker with authentication and access to the published Docker image (which runs as root) to write SQLite database files to arbitrary locations on the host filesystem. By crafting table names and namespace values with shell syntax, the attacker can cause code execution when Chromium is launched by Puppeteer and sources configuration files from the compromised path. This issue is resolved in Flowise version 3.1.3.
Potential Impact
An authenticated attacker can achieve arbitrary code execution on the host system running the vulnerable Flowise Docker container by writing malicious SQLite database files to system paths that Chromium will source as configuration files. This can lead to full system compromise due to the Docker container running as root and the ability to execute shell commands during Chromium startup.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed. Until upgrading, restrict access to the Docker container and avoid running it with root privileges if possible. Monitor vendor advisories for any additional mitigation guidance.
CVE-2026-69259: CWE-94: Improper Control of Generation of Code ('Code Injection') in FlowiseAI Flowise
Description
CVE-2026-69259 is a critical code injection vulnerability in FlowiseAI Flowise prior to version 3.1.3. The SQLite Record Manager node improperly allows user-controlled configuration to overwrite the SQLite database path. An authenticated attacker using the official Docker image running as root could write malicious SQLite database files to arbitrary system paths, such as /etc/chromium/exploit.conf. By controlling table names and namespace values, the attacker could inject shell syntax that executes when Puppeteer launches Chromium and sources configuration files from /etc/chromium/*.conf. This vulnerability is fixed in version 3.1.3.
CVSS v4.0
Score 9.4critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FlowiseAI Flowise versions before 3.1.3 contain a code injection vulnerability (CWE-94) in the SQLite Record Manager node. The node accepts an additionalConfig parameter that can overwrite the intended database path, allowing an attacker with authentication and access to the published Docker image (which runs as root) to write SQLite database files to arbitrary locations on the host filesystem. By crafting table names and namespace values with shell syntax, the attacker can cause code execution when Chromium is launched by Puppeteer and sources configuration files from the compromised path. This issue is resolved in Flowise version 3.1.3.
Potential Impact
An authenticated attacker can achieve arbitrary code execution on the host system running the vulnerable Flowise Docker container by writing malicious SQLite database files to system paths that Chromium will source as configuration files. This can lead to full system compromise due to the Docker container running as root and the ability to execute shell commands during Chromium startup.
Mitigation Recommendations
Upgrade Flowise to version 3.1.3 or later, where this vulnerability is fixed. Until upgrading, restrict access to the Docker container and avoid running it with root privileges if possible. Monitor vendor advisories for any additional mitigation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.853Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a721342bf8831d5391ad5ea
Added to database: 08/04/2026, 16:28:50 UTC
Last enriched: 08/04/2026, 16:41:25 UTC
Last updated: 08/04/2026, 16:41:25 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.