Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 4.0.0.1878.877 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:flowring:agentflow:*:*:*:*:*:*:*:* |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowring
Flowring agentflow |
|
| Vendors & Products |
Flowring
Flowring agentflow |
Tue, 10 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Title | Flowring|AgentFlow - Reflected Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-02-10T15:38:25.153Z
Reserved: 2026-02-06T11:02:50.450Z
Link: CVE-2026-2098
Updated: 2026-02-10T15:37:15.238Z
Status : Analyzed
Published: 2026-02-10T07:16:14.503
Modified: 2026-02-13T20:49:31.297
Link: CVE-2026-2098
No data.
OpenCVE Enrichment
Updated: 2026-04-18T13:00:08Z