Junglewise Threat Intelligence

CVE-2026-42157: Reconurge Flowsint stored XSS in map node markers

CVE-2026-42157 · Severity: info · CVSS 5.1 · Published 2026-05-12

Technologies: Reconurge Flowsint. Vendors: Reconurge.

Executive brief

Flowsint is an open-source tool used by cybersecurity professionals to visualize and investigate data during digital investigations. A security flaw allows an attacker to inject malicious code into map markers within the application. If a user views a compromised map and clicks on a malicious marker, the attacker could potentially steal their login credentials or hijack their session, compromising the integrity of the investigation.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Flowsint's map component. The root cause is located in 'flowsint-app/src/components/map/map.tsx', where the application uses Leaflet's 'bindPopup' method to render node labels or addresses. Because this method sets content using 'innerHTML' without proper sanitization, an attacker with permissions to create or modify nodes (via the /api/sketches/<sketch_id>/nodes/add endpoint) can inject arbitrary HTML/JavaScript. The payload executes in the context of any user who navigates to the map tab and clicks the affected marker. This can lead to the exfiltration of local storage data, including authorization tokens. The issue is resolved in version 1.2.3.

Affected products

  • reconurge Flowsint < 1.2.3

Timeline

  • 2026-04-29: advisory: GitHub Security Advisory published by maintainer
  • 2026-05-12: disclosed: CVE published to NVD
  • 2026-05-12: patched: Fix released in version 1.2.3

References

Related threats