Stored Cross-Site Scripting Vulnerability in Flowintel
CVE-2026-81753

5.1MEDIUM

Key Information:

Vendor

Flowintel

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81753?

A stored Cross-Site Scripting (XSS) vulnerability exists in Flowintel due to the inadequate neutralization of attacker-controlled markup within Mermaid blocks rendered in stored case notes. This flaw allows an attacker, authorized to create or edit notes, to store a malicious Mermaid payload. When another user views the affected note, it can lead to unauthorized JavaScript execution, potentially compromising user data and application security. The fixed version implements explicit detection and HTML escaping around token content, ensuring consistent protection against such attacks.

Affected Version(s)

flowintel 0 <= 3.3.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
David Cruciani
.