XSS Vulnerability in Flowsint OSINT Graph Exploration Tool by Reconurge
CVE-2026-42157
5.1MEDIUM
What is CVE-2026-42157?
Flowsint, an open-source OSINT graph exploration tool designed for cybersecurity investigations, contains a vulnerability that allows remote attackers to inject arbitrary HTML into map nodes. This occurs when a malicious label is created for a map node, leading to the potential execution of stored Cross-Site Scripting (XSS) when users interact with the map. It is crucial for users to upgrade to version 1.2.3 or later to mitigate this risk.
Affected Version(s)
flowsint < 1.2.3
