PT-2026-40466 · Flowsint · Flowsint

CVE-2026-42156

·

Published

2026-05-12

·

Updated

2026-05-13

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Flowsint versions prior to 1.2.3
Description Flowsint is an open-source OSINT graph exploration tool used for cybersecurity investigation, transparency, and verification. A remote attacker can create a node with a malicious type to escape an existing Cypher query, allowing the execution of arbitrary Cypher queries. Cypher is a graph query language used to interact with graph databases.
Recommendations Update to version 1.2.3.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42156
GHSA-H5M2-C2C5-968P

Affected Products

Flowsint