Known CVE
Flowise <= 3.0.5 - Account Takeover
Flowise versions 3.0.5 and earlier had a vulnerability in the forgot-password endpoint, which returned valid reset tokens without authentication—allowing attackers to reset passwords and take over accounts.
CVE-2025-58434
Critical2025CVSS 9.8CWE-306
cve2025 · flowise · ato · rce · unauth · vuln · ai
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website