Impact
Flowsint is an open‑source OSINT graph exploration tool that exhibits a broken access control flaw in all releases before version 1.2.3. The vulnerability allows an attacker to read sketch logs belonging to any user, potentially exposing sensitive investigative data. This weakness is identified as a missing authorization issue (CWE‑284).
Affected Systems
Any installed instance of Reconurge Flowsint version earlier than 1.2.3 is affected. The flaw is explicitly mitigated in release 1.2.3 and later.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not provided, and the vulnerability is not cataloged in the CISA KEV list, suggesting no widespread exploitation has been recorded. Based on the description, it is inferred that the likely attack vector is the web or API interface that serves sketch logs; an attacker with any user credential or potentially unauthenticated access can invoke the endpoint and retrieve logs. Because the flaw stems from insufficient authorization checks, the exploitation risk depends on whether the log endpoint is exposed to all users. With the absence of known exploits, the likelihood of immediate compromise is moderate, but the confidentiality impact warrants clearing the vulnerability through patching.
OpenCVE Enrichment