PT-2026-51145 · Flowise · Flowise

·

CVE-2025-71331

·

Published

2025-10-03

·

Updated

2026-06-23

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.0.8
Description Insufficient input filtering in chat messages and custom agent functions allows for cross-site scripting (XSS), a flaw where malicious scripts are injected into trusted websites. An attacker can execute malicious JavaScript in a victim's browser by sending an iframe payload, such as <iframe src="javascript:alert(document.cookie)">, through a chat box or by configuring a custom agent function to return a payload from an external website. This can lead to the theft of session data and cookies.
Recommendations Update to version 3.0.8.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71331
GHSA-4FR9-3X69-36WV

Affected Products

Flowise