Junglewise Threat Intelligence

CVE-2024-9148: Flowise stored cross-site scripting in Chat Embed

CVE-2024-9148 · Severity: low · CVSS 3.1 · Published 2024-09-25

Technologies: flowise (npm). Vendors: npm.

Executive brief

Flowise and its Chat Embed component are vulnerable to stored cross-site scripting (XSS) attacks due to lack of input sanitization. An attacker can inject malicious scripts that persist in the database and execute in other users' browsers, potentially leading to credential theft, account compromise, or malware distribution.

Technical details

Flowise and Flowise Chat Embed versions prior to 2.1.1 and 2.0.0 respectively suffer from a stored cross-site scripting (CWE-79) vulnerability caused by insufficient input validation and sanitization. An attacker can inject malicious JavaScript code through unsanitized input fields, which is stored in the database and executed when other users view the affected content. The attack requires user interaction (victim viewing the malicious content) but has a network attack vector with no authentication required. Successful exploitation allows full compromise of the victim's session, including data theft and unauthorized actions. Patches are available in Flowise 2.1.1 and Flowise Chat Embed 2.0.0.

Affected products

  • Flowise AI Flowise < 2.1.1
  • Flowise AI Flowise Chat Embed < 2.0.0

Timeline

  • 2024-09-25: disclosed: CVE-2024-9148 published
  • 2024-09-25: patched: Flowise 2.1.1 and Flowise Chat Embed 2.0.0 released with fixes

References

Related threats