Executive brief
Flowsint, an open-source tool used for cybersecurity investigations and data mapping, contains a security flaw that allows users to run unauthorized database commands. By creating a specially crafted data node, an attacker can bypass security restrictions to view or steal sensitive investigation data belonging to other users. This could lead to the exposure of confidential research, target identities, and organizational investigation history.
Technical details
A Cypher injection vulnerability exists in 'flowsint-api/app/api/routes/sketches.py' within the 'add_node' function. The application uses f-strings to interpolate the user-provided 'node_type' directly into a Neo4j MERGE query without proper sanitization or parameterization. An authenticated attacker can provide a malicious 'type' value in a JSON payload to the '/api/sketches/{sketch_id}/nodes/add' endpoint to escape the intended query. This allows for the execution of arbitrary Cypher queries, enabling the attacker to exfiltrate all nodes and relationships across all investigations in the Neo4j database. The issue is resolved in version 1.2.3.
Affected products
- reconurge Flowsint < 1.2.3
Timeline
- 2026-04-29: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE-2026-42156 published
- 2026-05-12: patched: Vulnerability fixed in version 1.2.3