PT-2024-39457 · Flowise+1 · Flowise+1

Joshua Martinelle

·

Published

2024-09-24

·

Updated

2024-09-30

·

CVE-2024-9148

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 2.1.1 Flowise Chat Embed versions prior to 2.0.0
Description The issue is related to a Stored Cross-Site vulnerability due to a lack of input sanitization.
Recommendations For Flowise versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. For Flowise Chat Embed versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-9148
GHSA-M5P9-XVXJ-64C8

Affected Products

Flowise
Flowise Chat Embed