The CVE-2026-69075 vulnerability affects FlowIntel, allowing an authenticated attacker to store malicious Vue expressions through multiple user-controlled or administrator-controlled fields. These persisted values were rendered inside DOM elements compiled by Vue, enabling the injection of Vue interpolation expressions. Successful exploitation could lead to arbitrary JavaScript execution in the victim's b [truncated]
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality located in app/case/task.py. An attacker with the ability to submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. The vulnerability stems from insufficient validation of both the URL sche [truncated]