A disclosed flaw in AppFlowy, tracked as CVE-2026-16007, allows an authenticated user to perform SQL injection through the search_term parameter in the /api/workspace/{workspace-id}/quick-note endpoint. The issue affects the quick-note search functionality and was traced to libs/database/src/quick_note.rs, creating a path for database exfiltration, modification, or deletion by any user with valid access.
The disclosure said AppFlowy indicated the issue no longer applied to its commercial AppFlowy Cloud codebase, but it did not confirm a fix or publish a remediation plan for the open-source, self-hosted version. Discussion on r/netsec amplified concerns that the SaaS offering had been addressed while community deployments remained vulnerable, leaving self-hosted administrators without clear patch guidance or assurance that the flaw had been resolved.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
The researchers informed AppFlowy that they intended to proceed with public disclosure of the SQL injection issue.
Project Black asked AppFlowy whether it intended to patch the open-source version after the vendor said the issue no longer affected its commercial cloud offering.
AppFlowy replied that the issue no longer applied to its commercial AppFlowy Cloud codebase. The response did not confirm a fix or address the open-source/self-hosted version.
Project Black contacted AppFlowy again because no further update had been provided on the vulnerability report.
AppFlowy responded to the researchers and said it was investigating the reported SQL injection vulnerability.
After receiving no response to the initial report, the researchers sent a follow-up to AppFlowy regarding the SQL injection issue.
Project Black reported an authenticated SQL injection vulnerability in AppFlowy, later tracked as CVE-2026-16007, to the vendor. The flaw affected the quick-note search functionality and could allow an authenticated user to exfiltrate, modify, or delete database contents.
Project Black published technical details for CVE-2026-16007, describing an authenticated SQL injection in AppFlowy's quick-note search endpoint and providing a proof-of-concept payload. The disclosure also highlighted uncertainty around remediation for the open-source/self-hosted version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.