← Back to CVE List
Vulnerability Intelligence Report
Flowise: Cypher Injection in GraphCypherQAChain

CVE-2026-41274

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. This vulnerability is fixed in 3.1.0.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.50%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-943 ↗CWE-943: Improper Neutralization of Special Elements in Data Query Logic

Affected Products & Versions

Vendor Product Affected Versions
FlowiseAI Flowise < 3.1.0 (affected)
FlowiseAI flowise-components < 3.1.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.504%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-04-18T14:01:46
Published2026-04-23T21:12:51
Last Updated2026-04-24T18:19:51

LINK COPIED TO CLIPBOARD