{"id":"CVE-2025-29192","title":"Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.","summary":"Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","cwe":["CWE-79"],"vendor":"flowiseai","product":"flowise","affected":["flowise < 3.0.5"],"patched":["flowise 3.0.5"],"published":"2025-10-06","updated":"2026-09-30","sourceUpdated":"2026-09-30T17:10:00.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-29192","references":[{"url":"https://github.com/FlowiseAI/Flowise/pull/4905","label":"cve@mitre.org"},{"url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.5","label":"cve@mitre.org"},{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7r4h-vmj9-wg42","label":"cve@mitre.org"},{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-7r4h-vmj9-wg42","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.0041,"epssPercentile":0.32761,"ingestedAt":"2026-09-30T17:13:20.712Z","slug":"CVE-2025-29192","body":"## Overview\n\nFlowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.\n\n## Affected\n\n- `flowise < 3.0.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `flowise 3.0.5`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}