VDB
KO
CRITICAL 9.6

GHSA-m5p9-xvxj-64c8

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Details

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / flowise-embed
Introduced in: 0 Fixed in: 2.0.0
Fix npm install flowise-embed@2.0.0
npm / flowise
Introduced in: 0 Fixed in: 2.1.1
Fix npm install flowise@2.1.1

References