Skip to content
FlowiseGHSA-m5p9-xvxj-64c8

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Medium9.6CVE-2024-9148 · Published Sep 25, 2024 · updated Sep 30, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
flowise
npm
< 2.1.12.1.1
Details and references

More Flowise advisories

All Flowise
DateAdvisory
Aug 272024Flowise Unauthenticated Denial of Service (DoS) vulnerability
CVE-2024-8182High7.5no fix yet
Aug 272024Flowise Authentication Bypass vulnerability
CVE-2024-8181High7.3no fix yet
Aug 52024Flowise Cross-site Scripting in api/v1/chatflows/id
CVE-2024-36422Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id
CVE-2024-37145Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in /api/v1/public-chatflows/id
CVE-2024-36423Medium6.1no fix yet
Aug 52024Flowise Cross-site Scripting in/api/v1/credentials/id
CVE-2024-37146Medium6.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.