FlowiseAI, Cross-Site Scripting (XSS), CVE-2024-31217 (Critical)

Listen to this Post

How the mentioned CVE works

The vulnerability CVE-2024-31217 in FlowiseAI stems from insufficient sanitization of user input within chat components and custom function nodes. An attacker can inject a malicious payload, such as an `