Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wq95-wr7m-26h4

Опубликовано: 06 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7r4h-vmj9-wg42. This link is maintained to preserve external references.

Original Description

Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.

Пакеты

Наименование

flowise

npm
Затронутые версииВерсия исправления

< 3.0.5

3.0.5

8.2 High

CVSS3

Дефекты

CWE-79

8.2 High

CVSS3

Дефекты

CWE-79