Unrated severityNVD Advisory· Published Jun 20, 2026
Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
CVE-2025-71331
Description
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., ) in a chat box, or by having a custom agent function return an XSS payload from an external website. The injected script executes in the victim's browser, enabling theft of cookies and session data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-4fr9-3x69-36wvmitrevendor-advisory
- www.vulncheck.com/advisories/flowise-cross-site-scripting-in-chat-messages-and-agent-workflowsmitrethird-party-advisory
News mentions
1- Flowise: Nine Vulnerabilities Including RCE and SSRF Disclosed in BatchVypr Intelligence · Jun 23, 2026