
CVE-2026-2099 AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are … https://www.cve.org/CVERecord?id=CVE-2026-2099
Post summary
The brief statement announces a stored XSS flaw in AgentFlow that permits authenticated remote attackers to inject persistent JavaScript, with no exploit, patch, or active exploitation details provided.

