CVE-2025-29189: SQL Injection
Published Apr 9, 2025
·Updated
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at PostgresVectorStores.
Affected Software
3 affected componentsFixes available
Flowise Flowise<=2.2.3
npm/flowise-components<=2.2.3
2.2.4
FlowiseAI Flowise<=2.2.3
Event History
Apr 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-29189?
CVE-2025-29189 has a high severity due to its potential to allow unauthorized access to sensitive data via SQL Injection.
2
How do I fix CVE-2025-29189?
To fix CVE-2025-29189, upgrade Flowise to a version newer than 2.2.3 where the vulnerability is patched.
3
What type of vulnerability is CVE-2025-29189?
CVE-2025-29189 is categorized as a SQL Injection vulnerability affecting the tableName parameter in Postgres_VectorStores.
4
What software is affected by CVE-2025-29189?
CVE-2025-29189 affects Flowise versions 2.2.3 and earlier.
5
What are the potential impacts of CVE-2025-29189?
The potential impacts of CVE-2025-29189 include data leakage, unauthorized data manipulation, and compromise of database integrity.