Executive brief
Flowintel, an intelligence management platform, failed to properly validate email addresses during login. Because validation was not enforced, attackers could submit malformed email input containing line-break characters that would be written directly to security audit logs without sanitization. This could allow attackers to forge or inject fake log entries, making it difficult to track actual security events and potentially covering unauthorized access attempts.
Technical details
The vulnerability is a log injection flaw caused by improper email validation on the login endpoint. The application called Email(email) to construct a WTForms validator object, but did not actually invoke the validation logic—it merely instantiated the object without executing it. As a result, malformed attacker-controlled email input bypassed validation and reached the logging layer. Since carriage return and line feed characters were not escaped, unauthenticated attackers could inject CR/LF sequences into both standard warning logs and the custom audit logger, creating new log lines or forging misleading entries. The fix corrects the validator invocation to Email()(form, form.email), switches to parameterized logging, and adds _sanitize_log_fragment() to encode line breaks. No network or authentication requirements exist; the flaw is reachable unauthenticated at the login endpoint.
Affected products
- Flowintel Flowintel >=3.3.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Commit 660b4cc introduces fix with corrected validator invocation and log sanitization