CVE-2026-2099: Flowring|AgentFlow - Stored Cross-Site Scripting
AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2099?
CVE-2026-2099 is classified as a high-severity vulnerability due to its potential to allow persistent JavaScript code injection.
How do I fix CVE-2026-2099?
Fixing CVE-2026-2099 involves implementing input validation and sanitization to prevent the injection of malicious scripts.
Who is affected by CVE-2026-2099?
CVE-2026-2099 affects users of Flowring's AgentFlow software, particularly authenticated users with the ability to input data.
What type of vulnerability is CVE-2026-2099?
CVE-2026-2099 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2026-2099 lead to data breaches?
Yes, CVE-2026-2099 can lead to data breaches by enabling attackers to execute malicious scripts in user browsers, potentially accessing sensitive information.