GITHUBEXPLOIT 9.8 CRITICAL

Exploit for Missing Authentication for Critical Function in Flowiseai Flowise_6D08DD28-3E6A-5370-AF92-CA6CC9DAC3D7

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Flowise-CVE-2025-58434-PasswordReset Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password without prior authentication. Includes a proof-of-concept script and...
Visit Original Source

Basic Information

ID 6D08DD28-3E6A-5370-AF92-CA6CC9DAC3D7
Published Apr 15, 2026 at 11:54

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.