CVE-2026-81659: Flowintel

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.

Affected products

  • Flowintel Flowintel: up to and including 3.3.0

Published 2026-08-27. Last modified 2026-08-28.