CVE-2024-9148: Flowise Stored Cross-Site Scripting
Published Sep 24, 2024
·Updated
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
Affected Software
4 affected componentsFixes available
npm/flowise<2.1.1
2.1.1
npm/flowise-embed<2.0.0
2.0.0
FlowiseAI Embed<2.0.0
FlowiseAI Flowise<2.1.1
Event History
Sep 24, 2024
CVE Published
via MITRE·01:13 PM
Data Sourced
via MITRE·01:13 PM
DescriptionSeverityWeakness
Sep 25, 2024
Advisory Published
via GitHub·03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-9148?
CVE-2024-9148 is considered a medium severity vulnerability due to its potential for exploitation via stored cross-site scripting.
2
How do I fix CVE-2024-9148?
To fix CVE-2024-9148, upgrade to Flowise version 2.1.1 or Flowise Embed version 2.0.0 or later.
3
What types of software are affected by CVE-2024-9148?
CVE-2024-9148 affects Flowise versions prior to 2.1.1 and Flowise Chat Embed versions prior to 2.0.0.
4
What are the consequences of exploiting CVE-2024-9148?
Exploiting CVE-2024-9148 can allow an attacker to execute malicious scripts in the context of the users' sessions.
5
Is there a workaround for CVE-2024-9148?
Currently, the only recommended solution for CVE-2024-9148 is to update to the fixed versions as there are no known workarounds.