Junglewise Threat Intelligence

CVE-2025-71337: FlowiseAI Flowise unverified email change in account profile endpoint

CVE-2025-71337 · Severity: high · CVSS 8.3 · Published 2026-06-23

Technologies: FlowiseAI Flowise. Vendors: FlowiseAI, npm.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a security flaw in its account management system. An authenticated user can change their account email address without providing their current password or verifying the change through the original email. This allows an attacker who has gained temporary access to an account to permanently take it over by changing the recovery email and locking out the legitimate owner.

Technical details

An unverified email change vulnerability exists in Flowise versions prior to 3.0.10 (specifically affecting 3.0.7 and earlier). The root cause is a lack of authentication or verification steps in the account profile endpoint; the application fails to require the current password or a confirmation link sent to the existing email address before updating the account's primary email. An attacker with low-privileged authenticated access can modify the email address used for login and password recovery. This enables full account takeover and persistence by leveraging the modified email to trigger password reset mechanisms. The issue is addressed in version 3.0.10.

Affected products

  • FlowiseAI Flowise <= 3.0.7, < 3.0.10

Timeline

  • 2025-11-12: advisory: Initial GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published and NVD record created

References

Related threats