PT-2026-82492 · Flowintel · Flowintel

·

CVE-2026-81662

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Flowintel versions 3.3.0 and later
Description Flowintel improperly trusts configuration keys provided to the alerts settings update endpoint. While configuration values are normalized to Python literals, the keys are used directly to construct and replace lines within the conf/config module.py file. The system uses requester-controlled keys in both the regular expression and the generated assignment f'{key} = {py val}', appending the assignment if the key is missing. Because the modified configuration module is subsequently reloaded using importlib.reload(), a code-generation boundary is created. This allows specially crafted configuration keys to alter the Python source structure, leading to the execution of attacker-controlled Python statements.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81662

Affected Products

Flowintel