Executive brief
Flowise is an open-source chatbot framework used to build and manage conversational AI applications. A stored cross-site scripting (XSS) vulnerability allows attackers to inject malicious HTML code through user prompts that gets saved in chat logs. When administrators view these logs, the injected code can execute in their browsers, potentially stealing admin credentials and authentication tokens—allowing the attacker to take over the admin account and access all user chat logs and API keys.
Technical details
The vulnerability exists because Flowise's chat log display allows unfiltered HTML tags (form, input, etc.) in user messages. An attacker can craft a prompt containing malicious HTML with JavaScript payloads (e.g., form input with formaction pointing to attacker-controlled JavaScript) that gets stored in the chat log. The stored payload executes when an administrator views the log in their browser, requiring user interaction (clicking an injected element). A successful exploit can lead to session hijacking, allowing the attacker to authenticate as an admin. The vulnerability affects all versions prior to 3.0.5, which has been patched.
Affected products
- FlowiseAI Flowise < 3.0.5
Timeline
- 2025-10-03: disclosed
- 2025-10-03: patched: Fixed in version 3.0.5