Flowsint Arbitrary HTML Injection Vulnerability Leading to Stored Cross-Site Scripting

Vulnerability

A stored cross-site scripting vulnerability has been identified in Flowsint, an open-source OSINT graph exploration tool, prior to version 1.2.3. The issue allows remote attackers to inject arbitrary HTML into map nodes. When the map tab is accessed and a node marker is clicked, the injected HTML is rendered, potentially executing malicious scripts. This vulnerability arises because the application uses innerHTML to display node labels, enabling HTML injection.

Impact

Exploitation of this vulnerability could lead to stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, create a map node in Flowsint prior to version 1.2.3 with a label that includes arbitrary HTML. Once the node is created, switch to the map tab and click on the node marker. The application will render the HTML, executing any embedded scripts.

Remediation

Users are advised to update Flowsint to version 1.2.3 or later, where this vulnerability has been fixed.

Added: May 12, 2026, 11:23 PM
Updated: May 12, 2026, 11:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
8.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.