Back to overview

CVE-2025-71328

HIGH
8.3
CVSS 3.1
Description
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session.

Metadata

CVE ID
CVE-2025-71328
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-08 20:44 UTC
Published
2026-06-25 21:41 UTC
Last updated
2026-06-25 21:41 UTC
Primary CWE
CWE-620
Unverified Password Change
Vendor / Product
Flowise / Flowise
Sources
cve.org  ·  NVD

Severity & Metrics

8.3 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products (1)
VendorProductPlatformVersions
Flowise Flowise 0 < 3.0.10, 3.0.10
Weakness (CWE)
CWESourceDescription
CWE-620 cna Unverified Password Change
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
8.3 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
References (2)
Back to overview