CVE-2025-50538High· 8.2▾ TwilightFlowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 2.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
14%
Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
flowise < 3.0.5Upgrade past the affected range:
flowise 3.0.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-29192High· 8.2Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
CVE-2025-71335High· 8.1Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password
CVE-2025-71336Critical· 9.8Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers
CVE-2025-71328High· 8.3Flowise before 3.0.10 contains an unverified password change vulnerability
CVE-2025-71333Critical· 9.8Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local
CVE-2025-71334Critical· 9.8Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations