CVE-2026-41274 PUBLISHED

Flowise: Cypher Injection in GraphCypherQAChain

Assigner: GitHub_M
Reserved: 18.04.2026 Published: 23.04.2026 Updated: 23.04.2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. This vulnerability is fixed in 3.1.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor FlowiseAI
Product Flowise
Versions
  • Version < 3.1.0 is affected
Vendor FlowiseAI
Product flowise-components
Versions
  • Version < 3.1.0 is affected

References

Problem Types

  • CWE-943: Improper Neutralization of Special Elements in Data Query Logic CWE