PT-2026-51490 · Flowise · Flowise

·

CVE-2025-71337

·

Published

2025-11-14

·

Updated

2026-06-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions 3.0.7 and earlier
Description An authenticated user can change the account email address, which serves as the login identifier and password-recovery channel, via the account profile endpoint. This process occurs without requiring confirmation from the original email address or the re-entry of the current password. By modifying the recovery email, an attacker can take over an account and abuse password reset mechanisms.
Recommendations Update to version 3.0.10.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71337
GHSA-X39M-3393-3QP4

Affected Products

Flowise