A critical vulnerability affecting FlowiseAI 's Flowise platform has been disclosed and allows authentication bypass , which can lead to complete account takeover with minimal effort.

The vulnerability, tracked as CVE-2025-58434, affects both cloud installations at cloud.flowiseai.com and self-hosted installations.
The vulnerability results from a fundamental design flaw in the /api/v1/account/forgot-password endpoint, which returns sensitive authentication tokens in API responses without proper verification.
When an attacker submits a password reset request, the endpoint responds with full user credentials, including the tempToken and the token expiration timestamp, effectively bypassing the email verification process.
See also: WhiteCobra: Malicious extensions in the VSCode market
The exploitation process only requires knowledge of the email address target's. Attackers can perform a simple POST request to the vulnerable endpoint using curl commands: curl -i -X POST https://
The server responds with a 201 Created status, revealing the complete user object containing the tempToken required for password reset operations.
Once obtained, the exposed tempToken can be reused directly on the /api/v1/account/reset-password endpoint to change the victim's credentials without any additional verification.

This second-stage attack uses another POST request containing the victim's email, the intercepted tempToken, and the attacker's chosen password.
The server processes this request with a 200 OK response, completing the account takeover.
See also: BitlockMove tool allows lateral movement & COM Hijacking
The vulnerability has a CVSS score of 9.8 (Critical), with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a network-accessible exploitation that does not require authentication, is easy to implement, and has a high impact on the confidentiality, integrity, and availability of the product. This classification reflects the potential for widespread automated exploitation against cloud and on-premises installations.
The vulnerability was reported by security researchers Zaddy6 and Arthurgervais.
Flowise Vulnerability – Protection
To address this critical flaw, the administrators of FlowiseAI and self-hosted installations must promptly implement the following measures:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
1. Ensure that the /api/v1/account/forgot-password endpoint never exposes the tempToken or any sensitive account information in the HTTP response. Instead, a generic success message such as {“message”:”If the email exists, you will receive reset instructions.”} should be returned, regardless of whether the email is registered.
2. Implement password reset token delivery exclusively via the verified email address user's. The API should generate a one-time tempToken, store it securely on the server side, and invalidate it on first use or after a short expiration period.
3. Add verification to the /api/v1/account/reset-password endpoint by checking that the tempToken matches the last generated token for the specific email, that it has not been used, and that it comes from the same client/IP that requested it.
4. Logging every password reset request along with the associated IP addresses and timestamps will help detect anomalous patterns.
5. Conduct a detailed code review for both cloud and self-hosted installations to confirm that there are no residual debug endpoints that expose sensitive data.
6. Implement strict rate limiting on password reset endpoints to prevent automated enumeration or brute-force attempts. Plan a patch release for version 3.0.5 that automates all of the above fixes and communicates clear upgrade instructions.
See also: VoidProxy: New phishing service steals credentials

Until the patch is available, administrators should consider placing the application behind a Web Application Firewall (WAF) to provide an additional layer of security.
By eliminating direct token exposure and enforcing strong verification and monitoring practices , organizations can mitigate the risk of account takeover and maintain the integrity of user credentials.
