S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 15, 2025

CVE-2025-58434 Scanner

CVE-2025-58434 Scanner - Account Takeover vulnerability in Flowise

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-58434
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073846433a596590d3d9c863 in version 3.0.6 secures password reset endpoints. Several recommended remediation steps are available. Do not return reset tokens or sensitive account details in API responses. Tokens must only be delivered securely via the registered email channel. Ensure `forgot-password` responds with a generic success message regardless of input, to avoid user enumeration. Require strong validation of the `tempToken` (e.g., single-use, short expiry, tied to request origin, validated against email delivery). Apply the same fixes to both cloud and self-hosted/local deployments. Log and monitor password reset requests for suspicious activity. Consider multi-factor verification for sensitive accounts.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Flowiseby FlowiseAI
<= 3.0.5
Updated Sep 9, 2026View on NVD →
Detail

Flowise is used by organizations to build AI agents visually, facilitating easy and interactive machine learning model creation and deployment. It is often utilized by developers, data scientists, and IT professionals seeking an intuitive way to engage in AI-driven tasks. The software supports integration into larger data ecosystems, allowing teams to create precise AI functionalities tailored to specific business needs. Due to its flexibility, Flowise is suitable for industries ranging from marketing to finance, assisting in predictive analysis and decision-making. A crucial aspect of its popularity is the capability to manage AI agents without extensive programming knowledge, making it accessible for various skill levels. Its comprehensive user interface enables rapid testing and deployment, enhancing the efficiency of AI development processes.

The Account Takeover vulnerability detected in Flowise allows unauthorized users to gain control over accounts. This vulnerability resides in the forgot-password endpoint, which provides valid reset tokens without authentication. Attackers can utilize this flaw to reset passwords and subsequently take over user accounts. This poses a significant security risk as unauthorized access can lead to data breaches and unauthorized manipulation of AI agents. Protecting sensitive information and ensuring secure access processes is vital to preventing such unauthorized activities. Organizations using Flowise need to be aware of this vulnerability to safeguard their AI and associated data effectively.

Technical details reveal that the vulnerability exists in the forgot-password API endpoint, where password reset tokens are issued without proper authentication. By sending a crafted request to the forgot-password endpoint, attackers can capture valid tokens due to improper validation processes. These valid tokens can then be used in subsequent requests to the reset-password endpoint, allowing an unauthorized password change. The lack of authentication checks in this process is the core of this vulnerability, permitting unauthorized account access under the guise of a legitimate user. This process exposes the service to potential account hijacks, further exacerbating the risk of data compromise and malicious activity.

Exploitation of this vulnerability could result in unauthorized access to user accounts, leading to potential data breaches and loss of sensitive information. Attackers could manipulate AI agents, alter data, and potentially sabotage business-critical systems. Without mitigation, these unauthorized activities may result in financial losses, reputational damage, and legal implications for organizations using Flowise. The security breach could also undermine trust with customers and stakeholders, affecting business operations adversely.

REFERENCES

Solution Advice
  • Implement two-factor authentication to enhance security during the password reset process.
  • Ensure rigorous validation and verification steps for issuing password reset tokens.
  • Monitor all account login activities for suspicious behavior, especially subsequent to password resets.
  • Conduct regular audits and updates to security protocols in Flowise to prevent vulnerabilities.
  • Educate users about creating strong, unique passwords to prevent easy compromises.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-58434 Scanner - Account Takeover vulnerability in Flowise | S4E