Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting
- Severity:
- Medium
Description
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
Recommendation
Update the flowise-embed package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.0.0
- Patched version(s): 2.0.0
References
Related Issues
- Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section - CVE-2024-47819
- Stored Cross-site Scripting (XSS) in excalidraw's web embed component - CVE-2024-32472
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- metascraper before v5.2.0 vulnerable to stored cross-site scripting - CVE-2018-3773
You might also like:
- Tags:
- npm
- flowise-embed
Anything's wrong? Let us know Last updated on September 30, 2024


