Vulnerabilities/

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Severity:
Medium

Description

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Recommendation

Update the flowise-embed package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-embed
Anything's wrong? Let us know Last updated on September 30, 2024