Executive brief
Flowintel is a case management and intelligence analysis platform. A stored cross-site scripting vulnerability in the note rendering feature allows an authenticated user to inject malicious JavaScript code into case notes by crafting a specially formatted Mermaid diagram. When other users view the affected case note, the injected JavaScript executes in their browser, potentially allowing an attacker to steal session tokens, modify data, or perform actions on behalf of the victim.
Technical details
A stored XSS vulnerability exists in Flowintel's Mermaid diagram rendering within case notes. The vulnerability stems from insufficient HTML escaping of attacker-controlled markup in Mermaid blocks before they are persisted and rendered to other users. An authenticated user with permission to create or edit notes can inject a crafted Mermaid payload that bypasses sanitization, resulting in arbitrary JavaScript execution when another user views the case note. The attack is persistent because the malicious payload is stored in the database and executed every time the note is accessed. The patch adds explicit Mermaid detection and HTML escaping around token content before rendering, and moves the wrapping logic earlier in page initialization for consistent protection across all Markdown instances.
Affected products
- Flowintel Flowintel 3.3.0 and later
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fix committed on GitHub; patch adds HTML escaping and moves wrapping logic earlier in initialization