Medium severity6.5NVD Advisory· Published Jun 24, 2026· Updated Jun 26, 2026
CVE-2025-71332
CVE-2025-71332
Description
Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including blind and error-based extraction of data from the credential table.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
flowisenpm | <= 2.2.7 | — |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/FlowiseAI/Flowise/security/advisories/GHSA-9c4c-g95m-c8cpnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-9c4c-g95m-c8cpghsaADVISORY
- www.vulncheck.com/advisories/flowise-sql-injection-in-importchatflows-api-via-chatflow-id-parameternvdThird Party Advisory
- github.com/FlowiseAI/Flowise/pull/4226ghsaWEB
News mentions
0No linked articles in our index yet.