SQL Injection: Hibernate in Flowise - #VU129622
Published: April 7, 2025 / Updated: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the importChatflows API when processing imported chatflow data. A remote privileged user can send a specially crafted import request with a malicious chatflow.id value to disclose sensitive information.
User interaction is required because a victim must import the crafted data.