Threats Tagged 'cve-2026-69259'
View all threats tagged with 'cve-2026-69259'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-69259'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-69259 is a critical code injection vulnerability in FlowiseAI's Flowise prior to version 3.1.3. The SQLite Record Manager node improperly handles user-controlled configuration, allowing an authenticated attacker to overwrite the SQLite database path. Exploiting this, an attacker running the published Docker image as root could write malicious SQLite databases to sensitive system paths such as /etc/chromium/exploit.conf. By controlling database content, the attacker could inject shell syntax that executes when Puppeteer launches Chromium and sources configuration files. This vulnerability is fixed in Flowise version 3.1.3. Join the discussion | CVE Database V5 | 08/04/2026, 16:05:19 UTC Added: 08/04/2026, 16:28:50 UTC |
Showing 1 to 1 of 1 result