Flowsint · Flowsint · CVE-2026-42159
**Name of the Vulnerable Software and Affected Versions**
Flowsint versions prior to 1.2.3
**Description**
Flowsint is an open-source OSINT graph exploration tool used for cybersecurity investigation, transparency, and verification. The software allows users to create investigations to manage sketches and analyses, where sketches consist of graphs containing nodes and relationships with target information. A remote attacker can create a node with a malicious description containing arbitrary HTML. When this node is selected, the HTML is rendered, which can trigger stored Cross-Site Scripting (XSS), a flaw where malicious scripts are permanently stored on the target server and executed in the victim's browser.
**Recommendations**
Update to version 1.2.3.