Vulnerability library
Security checkApril 24, 2026

Flowise: Cypher Injection in GraphCypherQAChain

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion.

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 3.0.13
  • Patched version(s): 3.1.0

References

Could your website be exposed too?

SmartScanner can check your website for Flowise: Cypher Injection in GraphCypherQAChain and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated April 24, 2026