---
id: CVE-2026-91934
title: >-
  Flowise versions before 3.1.4 fail to validate file paths in the SQL Database
  Chain node when connecting to SQLite databases, allowing authenticated
  attackers to write arbitrary files
summary: >-
  Flowise versions before 3.1.4 fail to validate file paths in the SQL Database
  Chain node when connecting to SQLite databases, allowing authenticated
  attackers to write arbitrary files. Attackers can write malicious SQLite
  databases to sy…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: FlowiseAI
product: Flowise
affected:
  - Flowise < 3.1.4
  - Flowise < 3.1.4
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:17:00.597'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91934'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-pwfj-wh95-7mwp
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-via-sql-database-chain
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T15:45:35.476133Z'
ingestedAt: '2026-09-15T15:39:12.926Z'
epss: 0.00737
epssPercentile: 0.52474
---

## Overview

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
