FlowiseAI, Stored Cross-Site Scripting, CVE-2024-XXXX (High)

Listen to this Post

How the CVE Works:

The vulnerability exists due to improper neutralization of user input in the FlowiseAI admin message viewing interface. A low-privileged user can interact with a deployed AI agent and submit a specially crafted message. This message contains a malicious payload, such as an `