CVE-CVE-2025-58434
Severity
CRITICAL
CVSS Score
9.8
Description
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai....
PoCs for CVE-CVE-2025-58434
Flowise-CVE-2025-58434-PasswordReset
General
Python
1
arensballiu
2026-04-15