Vulnerability Description
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-pwfj-wh95-7mwp
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-
FAQ
What is CVE-2026-91934?
CVE-2026-91934 is a vulnerability with a CVSS score of 8.8 (HIGH). Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can w...
How severe is CVE-2026-91934?
CVE-2026-91934 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-91934?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.