CVE-2025-29189: SQL Injection
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at PostgresVectorStores.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/flowise-componentsto a version that resolves this vulnerability.Fixed in 2.2.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29189?
CVE-2025-29189 has a high severity due to its potential to allow unauthorized access to sensitive data via SQL Injection.
How do I fix CVE-2025-29189?
To fix CVE-2025-29189, upgrade Flowise to a version newer than 2.2.3 where the vulnerability is patched.
What type of vulnerability is CVE-2025-29189?
CVE-2025-29189 is categorized as a SQL Injection vulnerability affecting the tableName parameter in Postgres_VectorStores.
What software is affected by CVE-2025-29189?
CVE-2025-29189 affects Flowise versions 2.2.3 and earlier.
What are the potential impacts of CVE-2025-29189?
The potential impacts of CVE-2025-29189 include data leakage, unauthorized data manipulation, and compromise of database integrity.