Junglewise Threat Intelligence

CVE-2026-81814: Flowintel XSS in calendar through case title

CVE-2026-81814 · Severity: info · CVSS 0 · Published 2026-08-27

Technologies: FlowIntel. Vendors: FlowIntel.

Executive brief

Flowintel is a case and intelligence management platform that displays events on a calendar. A user with permission to create or modify case titles can inject malicious HTML or JavaScript code that executes in the browsers of other users viewing the calendar, potentially leading to account compromise or data theft.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the calendar event rendering logic. The vulnerable code uses innerHTML to render calendar event titles derived directly from case titles, without sanitization. An attacker with case creation/modification privileges can inject script-capable HTML that persists in the database. When another user views the calendar, the browser interprets and executes the injected script. The fix replaces innerHTML with textContent, which treats input as plain text and prevents script execution. No CVSS score was provided by the vendor.

Affected products

  • Flowintel Flowintel 3.3.0 and earlier

Timeline

  • 2026-08-27: disclosed
  • 2026-08-18: patched: Fix commit dated 18 Aug 2026, published 27 Aug 2026

References

Related threats