CVE-2025-71328

8.3

Flowise · Flowise

Flowise before 3.0.10 contains an unverified password change vulnerability allowing authenticated users to modify account passwords without providing the current password.

Executive summary

A critical vulnerability in Flowise before 3.0.10 allows authenticated users to bypass password validation, creating a significant risk of full account takeover.

Vulnerability

This is an authentication-related flaw where an authenticated user can change their account password without supplying the current password, potentially leading to full account takeover if an attacker hijacks or coerces an authenticated session.

Business impact

The vulnerability carries a CVSS score of 8.3, indicating a high level of risk. A successful exploit could lead to unauthorized account takeover, resulting in complete compromise of the affected user's data and potential lateral movement within the Flowise environment.

Remediation

Immediate Action: Upgrade to Flowise version 3.0.10 or later immediately to apply the necessary security controls for password changes.

Proactive Monitoring: Review audit logs for suspicious account modification activity or unusual session behavior that could indicate unauthorized password changes.

Compensating Controls: Implement strict session management policies and ensure multi-factor authentication (MFA) is enforced wherever possible to mitigate the risk of session hijacking.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the potential for complete account takeover, organizations should prioritize the update to Flowise 3.0.10. Ensuring that all administrative and user sessions are authenticated and monitored is essential to preventing the exploitation of this vulnerability.

More Flowise CVEs