CVE-2025-58434: CWE-306: Missing Authentication for Critical Function in FlowiseAI Flowise
CVE-2025-58434 is a critical vulnerability in Flowise versions 3.0.5 and earlier where the forgot-password endpoint returns sensitive password reset tokens without requiring authentication. This flaw allows attackers to generate valid reset tokens for arbitrary users and reset their passwords, resulting in complete account takeover. The vulnerability affects both cloud and self-hosted deployments exposing the same API. Version 3.0.6 includes fixes that secure the password reset process by removing token exposure and enforcing proper validation and delivery methods.
AI Analysis
Technical Summary
FlowiseAI Flowise versions up to 3.0.5 have a missing authentication vulnerability (CWE-306) in the forgot-password endpoint. The endpoint returns a valid password reset temporary token in its response without any authentication or verification, enabling attackers to generate reset tokens for any user and reset their passwords directly. This leads to full account takeover. The vulnerability affects both cloud and self-hosted deployments exposing this API. The issue was fixed in version 3.0.6 by securing the password reset endpoints, ensuring tokens are only delivered securely via registered email, and enforcing strong validation of reset tokens.
Potential Impact
An attacker can obtain valid password reset tokens for arbitrary users without authentication, allowing them to reset passwords and take over user accounts completely. This compromises confidentiality, integrity, and availability of user accounts and potentially the entire system depending on account privileges.
Mitigation Recommendations
A fix is available in Flowise version 3.0.6 that secures the password reset endpoints by removing token exposure in API responses and enforcing secure token delivery via email. Users and administrators should upgrade to version 3.0.6 or later. Additionally, ensure the forgot-password endpoint returns generic success messages to prevent user enumeration, validate reset tokens as single-use with short expiry tied to request origin, and consider multi-factor verification for sensitive accounts. Apply these fixes to both cloud and self-hosted deployments.
CVE-2025-58434: CWE-306: Missing Authentication for Critical Function in FlowiseAI Flowise
Description
CVE-2025-58434 is a critical vulnerability in Flowise versions 3.0.5 and earlier where the forgot-password endpoint returns sensitive password reset tokens without requiring authentication. This flaw allows attackers to generate valid reset tokens for arbitrary users and reset their passwords, resulting in complete account takeover. The vulnerability affects both cloud and self-hosted deployments exposing the same API. Version 3.0.6 includes fixes that secure the password reset process by removing token exposure and enforcing proper validation and delivery methods.
CVSS v3.1
Score 9.8critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FlowiseAI Flowise versions up to 3.0.5 have a missing authentication vulnerability (CWE-306) in the forgot-password endpoint. The endpoint returns a valid password reset temporary token in its response without any authentication or verification, enabling attackers to generate reset tokens for any user and reset their passwords directly. This leads to full account takeover. The vulnerability affects both cloud and self-hosted deployments exposing this API. The issue was fixed in version 3.0.6 by securing the password reset endpoints, ensuring tokens are only delivered securely via registered email, and enforcing strong validation of reset tokens.
Potential Impact
An attacker can obtain valid password reset tokens for arbitrary users without authentication, allowing them to reset passwords and take over user accounts completely. This compromises confidentiality, integrity, and availability of user accounts and potentially the entire system depending on account privileges.
Mitigation Recommendations
A fix is available in Flowise version 3.0.6 that secures the password reset endpoints by removing token exposure in API responses and enforcing secure token delivery via email. Users and administrators should upgrade to version 3.0.6 or later. Additionally, ensure the forgot-password endpoint returns generic success messages to prevent user enumeration, validate reset tokens as single-use with short expiry tied to request origin, and consider multi-factor verification for sensitive accounts. Apply these fixes to both cloud and self-hosted deployments.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2025-09-01T20:03:06.531Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68c45b66055763ea6cf4ba8d
Added to database: 09/12/2025, 17:41:58 UTC
Last enriched: 07/10/2026, 09:46:20 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 974
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.