Miggo Logo

GHSA-7r4h-vmj9-wg42: Flowise Stored XSS vulnerability through logs in chatbot

5.3

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
Published
10/3/2025
Updated
10/3/2025
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
flowisenpm<= 3.0.7

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### **s*ription In t** ***t lo*, t**s lik* input *n* *orm *r* *llow**. T*is m*k*s * pot*nti*l vuln*r**ility w**r* *n *tt**k*r *oul* inj**t m*li*ious *TML into t** lo* vi* prompts. W**n *n **min vi*ws t** lo* *ont*inin* t** m*li*ious *TML, t** *tt**k*

Reasoning

No *n*lysis *v*il**l*