PT-2026-52614 · Flowise · Flowise

·

CVE-2025-71335

·

Published

2025-11-14

·

Updated

2026-06-26

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions 3.0.0 through 3.0.7
Description Flowise fails to invalidate existing sessions and session tokens after a user changes their password. This allows an attacker who possesses an active session, such as through a stolen session token or an unattended logged-in device, to remain authenticated as the user even after credentials have been rotated.
Recommendations Update Flowise to version 3.0.10 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71335
GHSA-X7RP-QJ2H-GHGW

Affected Products

Flowise