PT-2026-82492 · Flowintel · Flowintel
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Flowintel versions 3.3.0 and later
Description
Flowintel improperly trusts configuration keys provided to the alerts settings update endpoint. While configuration values are normalized to Python literals, the keys are used directly to construct and replace lines within the
conf/config module.py file. The system uses requester-controlled keys in both the regular expression and the generated assignment f'{key} = {py val}', appending the assignment if the key is missing. Because the modified configuration module is subsequently reloaded using importlib.reload(), a code-generation boundary is created. This allows specially crafted configuration keys to alter the Python source structure, leading to the execution of attacker-controlled Python statements.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowintel