CVE 8.7 HIGH

Flowise – Unverified Password Change via Account Settings_CVE-2025-71328

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Description

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session.

AI Analysis

Unverified password change vulnerability allowing full account takeover

Basic Information

ID CVE-2025-71328
Source VulnCheck
Published Jun 25, 2026 at 21:41

Affected Product

Vendor Flowise
Product Flowise
Affected Versions Flowise Flowise 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Flowise
Product Flowise
Version before 3.0.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.