Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
Flowise - Unverified Password Change via Account Settings
CVE-2025-71328
Description
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session.
Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-fjh6-8679-9pchmitrevendor-advisory
- www.vulncheck.com/advisories/flowise-unverified-password-change-via-account-settingsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.