A Cross Site Scripting vulnerability was reported in aiflowy version 2.1.2 or earlier. The vulnerability allows a remote attacker to obtain sensitive information via the UploadController.java file. This issue is considered a medium priority and requires immediate attention to prevent potential exploitation. Users should review the official CVE record and NVD details for further information.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T21:16:52.093Z and has not been modified since then. This vulnerability affects aiflowy version <= 2.1.2, allowing a remote attacker to obtain sensitive information via the JobUtil.java file. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. Users of aiflowy <= 2.1.2 should review [truncated]