Junglewise Threat Intelligence

CVE-2026-32311: Reconurge Flowsint command injection and container escape in org_to_asn

CVE-2026-32311 · Severity: critical · CVSS 9.8 · Published 2026-04-20

Technologies: Reconurge Flowsint. Vendors: Reconurge.

Executive brief

Flowsint, an open-source tool used for cybersecurity investigations and OSINT graph exploration, is vulnerable to a critical security flaw. An attacker can exploit a specific data transformation feature to execute malicious commands on the underlying server. This allows the attacker to bypass security containers and gain full administrative (root) control over the host machine, potentially leading to the theft of sensitive investigation data, service outages, or complete system compromise.

Technical details

A command injection vulnerability exists in Flowsint's 'org_to_asn' transformer due to improper neutralization of user-supplied input. Specifically, the 'name' parameter in a POST request to /api/transformers/org_to_asn/launch is interpolated into a shell command string and executed via subprocess.run with shell=True in 'to_asn.py'. A remote attacker can use shell metacharacters (e.g., $(command)) to achieve arbitrary code execution. Furthermore, because the Docker socket is mounted within the container, an attacker can leverage this access to perform a container escape and gain root privileges on the host operating system. The issue is addressed in version 1.2.3 and commit b52cbbb904c8013b74308d58af88bc7dbb1b055c.

Affected products

  • Reconurge Flowsint < v1.2.3

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory
  • 2026-04-20: patched: Fixed in version v1.2.3

References

Related threats