Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
Vulnerability Description
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="javascript:alert(document.cookie)">) in a chat box, or by having a custom agent function return an XSS payload from an external website. The injected script executes in the victim's browser, enabling theft of cookies and session data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71331
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- quitbug
References
More from Flowise
View All →Affected Vendor
Flowise
View all reports →