Executive brief
Flowise is a visual builder for AI agents that integrates with Neo4j graph databases. The GraphCypherQAChain component fails to sanitize user input before passing it to Neo4j for query execution, allowing attackers to inject arbitrary Cypher commands. An authenticated user with access to a vulnerable chatflow can read, modify, or delete database records, including sensitive data stored in the graph.
Technical details
The vulnerability is a Cypher injection flaw (CWE-943) in the GraphCypherQAChain node's run method (lines 193–219 of GraphCypherQAChain.ts). User-supplied input is passed directly to the chain's invoke method without any sanitization or parameterization, allowing an attacker to craft arbitrary Cypher queries. Exploitation requires network access to the Flowise API endpoint /api/v1/prediction/{flowId}, a valid chatflow ID, and (optionally) valid API credentials if authentication is enforced. An attacker can exfiltrate sensitive data, modify or delete nodes and relationships, enumerate database schema, and destroy the entire database using DETACH DELETE commands. The vulnerability affects all versions up to and including 3.0.13; version 3.1.0 and later include a fix.
Affected products
- FlowiseAI flowise <= 3.0.13
- FlowiseAI flowise-components <= 3.0.13
Timeline
- 2026-04-15: disclosed: Advisory published on GitHub
- 2026-04-16: advisory: OSV/GHSA entry published
- 2026-04-16: patched: Fix released in version 3.1.0