GITHUBEXPLOIT 10 CRITICAL

Exploit for Missing Authentication for Critical Function in Flowiseai Flowise_345530C2-1AD7-5814-91B6-2FD7F110CA8C

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

CVE-2025-58434CVE-2025-59528 CVE-2025-58434 Flowise = 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP Node Remote Code Execution. Usages: python3 RCE.py -d "xxxxxx.silentium.xxx"...
Visit Original Source

Basic Information

ID 345530C2-1AD7-5814-91B6-2FD7F110CA8C
Published Apr 14, 2026 at 06:50
Modified Apr 14, 2026 at 06:53

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.