PT-2026-82501 · Flowintel · Flowintel
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Flowintel versions 3.3.0 and later
Description
Stored Cross-Site Scripting (XSS) occurs when Mermaid blocks in case notes are rendered without sufficient neutralization of attacker-controlled markup. An attacker with permissions to create or edit notes can store a crafted Mermaid payload that executes JavaScript in the browser of any user who views the affected case note.
Recommendations
Update Flowintel to a version where Mermaid detection and HTML escaping are implemented for token content and wrapping logic is moved earlier in page initialization.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowintel