Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a map node with a malicious label that contains arbitrary HTML. When the map tab is selected and a map node marker is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixed in 1.2.3.
CVSS
No CVSS.
References
Configurations
No configuration.
History
18 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/reconurge/flowsint/security/advisories/GHSA-gj93-2vcq-729w - |
12 May 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 23:16
Updated : 2026-06-17 10:47
NVD link : CVE-2026-42157
Mitre link : CVE-2026-42157
CVE.ORG link : CVE-2026-42157
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
