VYPR
Vendor

Flowintel

Products
1
CVEs
13
Across products
13
Status
Private

Products

1

Recent CVEs

13
  • CVE-2026-9813CriMay 28, 2026
    risk 0.57cvss 9.9epss 0.00

    FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request…

  • CVE-2026-81826CriAug 27, 2026
    risk 0.52cvss —epss 0.00

    Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token—the victim changing their password…

  • CVE-2026-81818HigAug 27, 2026
    risk 0.49cvss —epss 0.00

    Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent them from editing a full…

  • CVE-2026-81662HigAug 27, 2026
    risk 0.49cvss —epss 0.01

    Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding keys were used directly when constructing and replacing lines in…

  • CVE-2026-81743HigAug 27, 2026
    risk 0.42cvss —epss 0.00

    Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log directory. Because the application constructs the log destination from this configurable value, an…

  • CVE-2026-81817HigAug 27, 2026
    risk 0.40cvss —epss 0.00

    Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a case identifier and a task identifier, but previously they did not enforce that the task…

  • CVE-2026-81659HigAug 27, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.

  • CVE-2026-81827MedAug 27, 2026
    risk 0.38cvss —epss 0.00

    Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object. Consequently, malformed attacker-controlled email input could continue…

  • CVE-2026-69075MedAug 3, 2026
    risk 0.38cvss —epss 0.00

    FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile attributes, organisation names, and…

  • CVE-2026-81819MedAug 27, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be returned, but previously had no role restriction beyond general API authentication.…

  • CVE-2026-81820MedAug 27, 2026
    risk 0.26cvss —epss 0.00

    Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * object UUID; * object name; * attribute value; * attribute type; * comment; * first/last seen values; * IDS flag. …

  • CVE-2026-81814MedAug 27, 2026
    risk 0.26cvss —epss 0.00

    Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the browser when another user…

  • CVE-2026-81753MedAug 27, 2026
    risk 0.26cvss —epss 0.01

    Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later rendered for other users, an attacker with permission to create or edit a note…