CVE-2025-71332

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
24/06/2026
Last modified:
26/06/2026

Description

Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including blind and error-based extraction of data from the credential table.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* 2.2.7 (including)