PT-2025-40841 · Flowise · Flowise

Mikensec

·

Published

2025-10-03

·

Updated

2025-10-06

·

CVE-2025-50538

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.0.5
Description The software contains a cross-site scripting issue that can be triggered when an administrator views the chat log through an IFRAME element. This could potentially lead to session hijacking and data theft.
Recommendations Update to version 3.0.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-50538
GHSA-7RGR-72HP-9WP3
GHSA-964P-J4GG-MHWC

Affected Products

Flowise