PT-2026-51145 · Flowise · Flowise
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.0.8
Description
Insufficient input filtering in chat messages and custom agent functions allows for cross-site scripting (XSS), a flaw where malicious scripts are injected into trusted websites. An attacker can execute malicious JavaScript in a victim's browser by sending an iframe payload, such as
<iframe src="javascript:alert(document.cookie)">, through a chat box or by configuring a custom agent function to return a payload from an external website. This can lead to the theft of session data and cookies.Recommendations
Update to version 3.0.8.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowise