CVE-2024-9148
CRITICALFlowise < 2.1.1 - Stored Cross-Site Scripting in Chat Embed
Title source: llmDescription
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
References (1)
Core 1
Core References
Exploit, Vendor Advisory
https://www.tenable.com/security/research/tra-2024-40
Scores
CVSS v3
9.6
EPSS
0.0193
EPSS Percentile
83.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (4)
flowiseai/embed
< 2.0.0
flowiseai/flowise
< 2.1.1
npm/flowise
0 - 2.1.1npm
npm/flowise-embed
0 - 2.0.0npm
Published
Sep 25, 2024
Tracked Since
Feb 18, 2026