CVE-2025-71331: Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="javascript:alert(document.cookie)">) in a chat box, or by having a custom agent function return an XSS payload from an external website. The injected script executes in the victim's browser, enabling theft of cookies and session data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flowiseto a version that resolves this vulnerability.Fixed in 3.0.8
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71331?
The severity of CVE-2025-71331 is medium with a score of 6.1.
How do I fix CVE-2025-71331?
To fix CVE-2025-71331, update Flowise to version 3.0.8 or later.
What type of vulnerability is CVE-2025-71331?
CVE-2025-71331 is a cross-site scripting (XSS) vulnerability.
What can an attacker do with CVE-2025-71331?
An attacker can inject malicious JavaScript into chat messages and agent functions using this XSS vulnerability.
Which software is affected by CVE-2025-71331?
The affected software for CVE-2025-71331 is Flowise before version 3.0.8.