Stored Cross-Site Scripting Vulnerability in Flowintel
CVE-2026-81753
5.1MEDIUM
What is CVE-2026-81753?
A stored Cross-Site Scripting (XSS) vulnerability exists in Flowintel due to the inadequate neutralization of attacker-controlled markup within Mermaid blocks rendered in stored case notes. This flaw allows an attacker, authorized to create or edit notes, to store a malicious Mermaid payload. When another user views the affected note, it can lead to unauthorized JavaScript execution, potentially compromising user data and application security. The fixed version implements explicit detection and HTML escaping around token content, ensuring consistent protection against such attacks.
Affected Version(s)
flowintel 0 <= 3.3.0
