Executive brief
Flowintel is an open-source intelligence platform used to collect and manage threat intelligence data. A vulnerability in its alerts settings configuration endpoint allows an attacker to inject arbitrary Python code that executes on the server, potentially compromising the entire system and all data it manages.
Technical details
The vulnerability is a code injection flaw in the alerts settings update endpoint that processes configuration keys and values. While configuration values are sanitized into Python literals, the keys are used directly in string formatting to generate Python source code (f'{key} = {py_val}'), which is then written to and reloaded from conf/config_module.py using importlib.reload(). An attacker can supply specially crafted configuration keys containing Python syntax to break out of the assignment context and inject arbitrary statements. The attack requires network access to the alerts settings endpoint and the ability to send a crafted request; no authentication bypass is explicitly documented but endpoint access controls should be verified. The fix, available in commit d36171e, properly sanitizes configuration keys to prevent syntax injection.
Affected products
- Flowintel Flowintel 3.3.0 and later
Timeline
- 2026-08-27: disclosed: Published on NVD
- 2026-08-27: patched: Fix available in commit d36171e