CVE-2024-37146
JavaScript vulnerability analysis and mitigation

Overview

Flowise, a drag & drop user interface for building customized large language model flows, contains a reflected cross-site scripting vulnerability in version 1.4.3. The vulnerability is specifically located in the /api/v1/credentials/id endpoint. When using the default unauthenticated configuration, attackers can craft malicious URLs to inject JavaScript into user sessions (GitHub Advisory).

Technical details

The vulnerability occurs when the chatflow ID is not found, causing its value to be reflected in the 404 page with text/html content type. This reflection allows attackers to attach arbitrary scripts to the page. The vulnerability has been assigned a CVSS v3.1 Base Score of 6.1 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network accessibility, low attack complexity, no privileges required, and user interaction required (NVD).

Impact

If successfully exploited, attackers can steal sensitive information from users, create false popups, or redirect users to other websites without interaction. The vulnerability can be chained with path injection to allow attackers without direct access to Flowise to read arbitrary files from the Flowise server (GitHub Advisory).

Exploitability

The vulnerability is exploitable when Flowise is running with default configuration (unauthenticated). An attacker can craft a specially crafted URL that injects Javascript into user sessions. The attack requires user interaction but has low complexity in execution (GitHub Advisory).

Mitigation and workarounds

As of the time of publication, no known patches are available for this vulnerability (NVD).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73421CRITICAL9.1
  • JavaScript logoJavaScript
  • next-auth
NoYesAug 13, 2026
CVE-2026-73420CRITICAL9.1
  • JavaScript logoJavaScript
  • next-auth
NoYesAug 13, 2026
CVE-2026-73305HIGH8.8
  • JavaScript logoJavaScript
  • @budibase/server
NoNoAug 13, 2026
CVE-2026-73408HIGH7.6
  • JavaScript logoJavaScript
  • @budibase/server
NoNoAug 13, 2026
CVE-2026-73428MEDIUM4.6
  • JavaScript logoJavaScript
  • action_text-trix
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management