Executive brief
Flowise is an open-source platform for building AI applications and workflows. The forgot-password endpoint exposes valid password reset tokens and sensitive account information to anyone without authentication, allowing attackers to reset arbitrary user passwords and take over accounts with only knowledge of an email address. This affects both Flowise Cloud and self-hosted deployments, enabling complete compromise of any account including administrators.
Technical details
The vulnerability is an authentication bypass in the /api/v1/account/forgot-password endpoint, which returns sensitive user data including a valid tempToken and token expiry timestamp without requiring any authentication or email verification. The root cause is insecure information disclosure combined with missing access controls on password reset functionality. An unauthenticated attacker can POST an arbitrary email address, receive a valid reset token in the response, and immediately use it to reset the target account's password via /api/v1/account/reset-password. No user interaction, email verification, or prior access is required. The vulnerability affects all Flowise versions prior to 3.0.6, and has been patched in version 3.0.6 and later.
Affected products
- FlowiseAI Flowise < 3.0.6
Timeline
- 2025-09-12: disclosed: GHSA-wgpv-6j63-x5ph and CVE-2025-58434 published
- 2025-09-12: patched: Fix available in version 3.0.6