{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-71331", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-06-19T12:57:55.856Z", "datePublished": "2026-06-20T15:24:39.877Z", "dateUpdated": "2026-06-22T13:51:35.335Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-06-20T15:24:39.877Z" }, "datePublic": "2025-10-03T00:00:00.000Z", "title": "Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows", "descriptions": [ { "lang": "en", "value": "Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g.,