
Cloud Vulnerability DB
A community-led vulnerabilities database
Flowise, a drag & drop user interface for building customized large language model flows, contains a reflected cross-site scripting vulnerability in version 1.4.3. The vulnerability is specifically located in the /api/v1/credentials/id endpoint. When using the default unauthenticated configuration, attackers can craft malicious URLs to inject JavaScript into user sessions (GitHub Advisory).
The vulnerability occurs when the chatflow ID is not found, causing its value to be reflected in the 404 page with text/html content type. This reflection allows attackers to attach arbitrary scripts to the page. The vulnerability has been assigned a CVSS v3.1 Base Score of 6.1 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network accessibility, low attack complexity, no privileges required, and user interaction required (NVD).
If successfully exploited, attackers can steal sensitive information from users, create false popups, or redirect users to other websites without interaction. The vulnerability can be chained with path injection to allow attackers without direct access to Flowise to read arbitrary files from the Flowise server (GitHub Advisory).
The vulnerability is exploitable when Flowise is running with default configuration (unauthenticated). An attacker can craft a specially crafted URL that injects Javascript into user sessions. The attack requires user interaction but has low complexity in execution (GitHub Advisory).
As of the time of publication, no known patches are available for this vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."