High severity8.3NVD Advisory· Published Jun 25, 2026· Updated Jun 29, 2026
CVE-2025-71328
CVE-2025-71328
Description
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-fjh6-8679-9pchnvdExploitVendor Advisory
- www.vulncheck.com/advisories/flowise-unverified-password-change-via-account-settingsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.