What is CVE-2026-69259?
A security vulnerability in Flowise's SQLite Record Manager node allows user-controlled `additionalConfig` to be processed without proper validation, potentially leading to database manipulation. The issue affects versions prior to 3.1.3, and users should upgrade to the patched version immediately.
Azərbaycanca: Flowise LLM axın qurucu interfeysində SQLite Record Manager node-unun istifadəçi tərəfindən idarə olunan `additionalConfig` parametrlərini düzgün yoxlamadığı üçün təhlükəsizlik boşluğu aşkarlanıb. Bu zəiflikdən istifadə edərək hücumçu potensial olaraq verilənlər bazasına müdaxilə edə bilər. İstifadəçilərə 3.1.3 versiyasına yeniləmə tövsiyə olunur.
FAQ2
What causes the CVE-2026-69259 vulnerability affecting the SQLite Record Manager node in Flowise?
The vulnerability arises because the node does not properly validate user-controlled `additionalConfig` parameters, potentially allowing an attacker to manipulate the database.
To which version should users upgrade to protect against CVE-2026-69259?
Users are advised to upgrade to version 3.1.3 of Flowise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.