Flowise versions 3.0.5 and earlier had a vulnerability in the forgot-password endpoint, which returned valid reset tokens without authentication—allowing attackers to reset passwords and take over accounts.
id: CVE-2025-58434
info:
name: Flowise <= 3.0.5 - Account Takeover
author: nukunga[seunghyeonJe
...