SQL Injection: Hibernate in Flowise - #VU129622
Published: April 7, 2025 / Updated: May 4, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the importChatflows API when processing imported chatflow data. A remote privileged user can send a specially crafted import request with a malicious chatflow.id value to disclose sensitive information.
User interaction is required because a victim must import the crafted data.