PT-2026-82500 · Flowintel · Flowintel
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowintel versions 3.3.0 and later
Description
Flowintel allows the
LOG FILE configuration value to be modified via system settings without restricting it to the intended log directory. This allows an administrator to set LOG FILE to an arbitrary filesystem path. Because attackers can influence the content being logged, they can write controlled data into unintended files. This can lead to remote code execution through an exploitation chain where an attacker injects a template into a file and abuses the application rendering behavior. The fix involves the validate log file name() function to reject absolute paths, traversal, Windows paths, null bytes, and directory components, while centralizing path construction through resolve log file path().Recommendations
Update Flowintel to a version where
LOG FILE is removed from web-editable settings and path validation is implemented.
As a temporary mitigation, restrict administrative access to system settings to prevent the modification of the LOG FILE configuration value.Exploit
Fix
RCE
Path traversal
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowintel