
CVE-2026-2098 AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in u… https://www.cve.org/CVERecord?id=CVE-2026-2098
Post summary
The statement reports a reflected XSS vulnerability (CVE-2026-2098) in AgentFlow that permits unauthenticated remote attackers to run arbitrary JavaScript, but does not mention PoC, exploit, active exploitation, or a patch.
