flowintel
11 known vulnerabilities in flowintel, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-81827 CVSS 6.9 medium Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform…
- CVE-2026-81826 CVSS 9.1 critical Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an…
- CVE-2026-81820 CVSS 5.1 medium Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * object UUID; * object…
- CVE-2026-81819 CVSS 5.3 medium Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id…
- CVE-2026-81818 CVSS 8.6 high Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check…
- CVE-2026-81817 CVSS 7.2 high Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task…
- CVE-2026-81814 CVSS 5.1 medium Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user…
- CVE-2026-81753 CVSS 5.1 medium Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled…
- CVE-2026-81743 CVSS 7.5 high Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a…
- CVE-2026-81662 CVSS 8.6 high Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration…
- CVE-2026-81659 CVSS 7.1 high Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way…