Impact
Authenticated users with access to the qcuiknote feature can inject arbitrary SQL statements into the underlying database. This flaw allows the execution of malicious queries that can read or modify data, resulting in potential data exfiltration. The vulnerability is officially classified as CWE‑89, a classic example of an injection flaw.
Affected Systems
AppFlowy‑IO’s AppFlowy‑Cloud offering is affected, particularly any installations that expose the qcuiknote feature to authenticated users. No specific product version was enumerated, so all current releases that include this feature should be considered vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS base score of 7.1, the vulnerability falls into the medium‑to‑high severity range. Because it requires authentication, an attacker must first gain legitimate user access before exploitation can occur. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. Nonetheless, the potential for confidential data loss warrants prompt remediation.
OpenCVE Enrichment