Skip to content

Known CVE

Flowise <= 3.0.5 - Account Takeover

Flowise versions 3.0.5 and earlier had a vulnerability in the forgot-password endpoint, which returned valid reset tokens without authentication—allowing attackers to reset passwords and take over accounts.

CVE-2025-58434

Critical2025CVSS 9.8CWE-306

cve2025 · flowise · ato · rce · unauth · vuln · ai

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website