CVE-2025-71328
8.3Flowise · Flowise
Flowise before 3.0.10 contains an unverified password change vulnerability allowing authenticated users to modify account passwords without providing the current password.
Executive summary
A critical vulnerability in Flowise before 3.0.10 allows authenticated users to bypass password validation, creating a significant risk of full account takeover.
Vulnerability
This is an authentication-related flaw where an authenticated user can change their account password without supplying the current password, potentially leading to full account takeover if an attacker hijacks or coerces an authenticated session.
Business impact
The vulnerability carries a CVSS score of 8.3, indicating a high level of risk. A successful exploit could lead to unauthorized account takeover, resulting in complete compromise of the affected user's data and potential lateral movement within the Flowise environment.
Remediation
Immediate Action: Upgrade to Flowise version 3.0.10 or later immediately to apply the necessary security controls for password changes.
Proactive Monitoring: Review audit logs for suspicious account modification activity or unusual session behavior that could indicate unauthorized password changes.
Compensating Controls: Implement strict session management policies and ensure multi-factor authentication (MFA) is enforced wherever possible to mitigate the risk of session hijacking.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the potential for complete account takeover, organizations should prioritize the update to Flowise 3.0.10. Ensuring that all administrative and user sessions are authenticated and monitored is essential to preventing the exploitation of this vulnerability.