Executive brief
Flowise is an open-source platform for building conversational AI chatbots. The application fails to sanitize HTML tags in chat logs, allowing attackers to inject malicious code that executes when administrators view the logs. An attacker could steal admin credentials or session tokens, gaining full control of the chatbot platform and access to user data and API keys.
Technical details
This is a stored Cross-Site Scripting (XSS) vulnerability in Flowise's chat logging feature, caused by insufficient HTML sanitization. Attackers can inject malicious FORM and INPUT elements with event handlers (e.g., formaction="javascript:...") through user prompts; these payloads are stored in the logs and executed in the admin's browser when viewing them. The attack requires user interaction (admin clicking a specially crafted image element) but no authentication. Successful exploitation allows credential theft and account hijacking. The vulnerability affects all versions before 3.0.5, which was released to address this issue.
Affected products
- FlowiseAI Flowise before 3.0.5
Timeline
- 2025-10-03: disclosed
- 2025-10-05: patched: Version 3.0.5 released