Junglewise Threat Intelligence

FlowiseAI Flowise stored XSS in message view

Severity: low · CVSS 3.1 · Published 2025-10-06

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

FlowiseAI Flowise is an open-source platform for building conversational AI agents. A stored cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript through chat messages that executes when administrators view the message logs. This enables attackers to steal admin credentials and session tokens stored in browser memory, potentially compromising the entire admin panel and all customer data.

Technical details

A stored XSS vulnerability exists in FlowiseAI Flowise prior to version 3.0.8 due to insufficient input sanitization when displaying stored user messages in the admin interface. An attacker can inject an iframe element with a srcdoc attribute containing arbitrary JavaScript into the chat interface. When an administrator views messages via the "View Messages" button, the malicious script executes in the admin's browser context with access to localStorage, enabling exfiltration of credentials and sensitive data. The vulnerability requires no elevated privileges to exploit and user interaction from the admin is required. A patch is available in version 3.0.8 and later.

Affected products

  • FlowiseAI Flowise <3.0.8

Timeline

  • 2025-10-03: disclosed
  • 2025-10-06: patched: Version 3.0.8 released

References

Related threats