Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Flowise - #VU129614
Published: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of script-related html tags in a web page in chat message and agentflow content rendering when rendering untrusted content. A remote attacker can inject a malicious script payload to execute arbitrary script code in a victim's browser.
User interaction is required to view a crafted chat message or agentflow content.