XSS Vulnerability in Flowsint OSINT Graph Exploration Tool by Reconurge
CVE-2026-42157

5.1MEDIUM

Key Information:

Vendor

Reconurge

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-42157?

Flowsint, an open-source OSINT graph exploration tool designed for cybersecurity investigations, contains a vulnerability that allows remote attackers to inject arbitrary HTML into map nodes. This occurs when a malicious label is created for a map node, leading to the potential execution of stored Cross-Site Scripting (XSS) when users interact with the map. It is crucial for users to upgrade to version 1.2.3 or later to mitigate this risk.

Affected Version(s)

flowsint < 1.2.3

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.