Path traversal in Flowise - #VU146551
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to conduct stored cross-site scripting.
The vulnerability exists due to path traversal in the Sql Database Chain node when accepting a user-supplied sqlite file path. A remote user can supply a crafted sqlite database path and write malicious HTML content into the frontend build directory to conduct stored cross-site scripting.
User interaction is required for a victim to visit the attacker-written HTML file served by the application.