No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 14 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Reconurge
Reconurge flowsint |
|
| Vendors & Products |
Reconurge
Reconurge flowsint |
Thu, 14 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites, etc) within these nodes and relationships. A remote attacker can create a node with a malicious description that contains arbitrary HTML. When the node is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixed in 1.2.3. | |
| Title | Flowsint: Stored XSS in description of node | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:21:16.068Z
Reserved: 2026-04-24T17:15:21.836Z
Link: CVE-2026-42159
Updated: 2026-05-14T18:21:09.032Z
Status : Awaiting Analysis
Published: 2026-05-14T16:16:20.993
Modified: 2026-05-14T19:16:35.603
Link: CVE-2026-42159
No data.
OpenCVE Enrichment
Updated: 2026-05-14T18:00:14Z