← Back to BrewedIntel
otherlow

Apr 20, 2026 • Joshua Martinelle

Flowise - Cypher Injection in GraphCypherQAChain

Flowise - Cypher Injection in GraphCypherQAChain The GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline...

Source
Tenable Research Advisories
Category
other
Severity
low

Summary

Flowise - Cypher Injection in GraphCypherQAChain The GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. Joshua Martinelle Mon, 04/20/2026 - 11:01

Published Analysis

Flowise - Cypher Injection in GraphCypherQAChain The GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. Joshua Martinelle Mon, 04/20/2026 - 11:01 Flowise - Cypher Injection in GraphCypherQAChain The GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. Joshua Martinelle Mon, 04/20/2026 - 11:01