CRITICAL
Flowise: Cypher Injection in GraphCypherQAChain
Published Apr 23, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.73%
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. This vulnerability is fixed in 3.1.0.
Affected products
-
- Version < 3.1.0StatusaffectedConstraints-
- Version
-
- Version < 3.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| FlowiseAI | Flowise | n/a |
| ||||||
| FlowiseAI | Flowise-Components | n/a |
|
No data.
No Red Hat product state for this CVE.
flowise
npm
Introduced 0 Fixed 3.1.0flowise-components
npm
Introduced 0 Fixed 3.1.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | flowise | 0 | 3.1.0 |
| npm | flowise-components | 0 | 3.1.0 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25313 Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-28g4-38q8-3cwc exploitx_refsource_CONFIRMVendor Advisory
- https://github.com/advisories/GHSA-28g4-38q8-3cwc Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41274
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25313 | Advisory | |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-28g4-38q8-3cwc | exploitx_refsource_CONFIRMVendor Advisory | |
| https://github.com/advisories/GHSA-28g4-38q8-3cwc | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41274 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 18, 2026
Link CVE-2026-41274
CISA Vulnrichment
Updated Apr 24, 2026
ENISA EUVD
EUVD-2026-25313 GHSA-28G4-38Q8-3CWC Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 24, 2026
Exploited since n/a
Link EUVD-2026-25313