CVE-2024-9148: Flowiseai Embed

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Affected products

  • Flowiseai Embed: before 2.0.0 (fixed in 2.0.0)
  • Flowiseai Flowise: before 2.1.1 (fixed in 2.1.1)

Published 2024-09-25. Last modified 2026-06-17.