HIGH
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log
Published Oct 6, 2025
8.2
HIGHCVSS 3.1
EPSS 0.41%
Description
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
Affected products
-
Affected
- ≥ 0, < 3.0.5
No data.
No Red Hat product state for this CVE.
flowise
npm
Introduced 0 Fixed 3.0.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | flowise | 0 | 3.0.5 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32213 Advisory
- https://github.com/FlowiseAI/Flowise/commit/9a06a85a8ddcbaeca1342827a5fea9087a587d97
- https://github.com/FlowiseAI/Flowise/pull/4905 Patch
- https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.5 Release Notes
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7r4h-vmj9-wg42 exploitThird Party Advisory
- https://github.com/advisories/GHSA-7r4h-vmj9-wg42 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-29192
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 6, 2025
Updated Oct 6, 2025
Reserved Mar 11, 2025
Link CVE-2025-29192
CISA Vulnrichment
Updated Oct 6, 2025
Red Hat
No data
GitHub
Link GHSA-7R4H-VMJ9-WG42