A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been classified as problematic. The impacted element is an unknown function of the file packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts of the component SQLite Record Manager. Performing a manipulation of the argument additionalConfig results in sql injection.
This vulnerability is reported as CVE-2026-69259. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.