
CVE-2025-71331 Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attack… https://www.cve.org/CVERecord?id=CVE-2025-71331
Post summary
A new XSS vulnerability (CVE‑2025‑71331) was disclosed in Flowise versions before 3.0.8, caused by poor input filtering in chat messages and custom agent functions.


