{"id":"CVE-2025-71335","title":"Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password","summary":"Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session t…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-613"],"vendor":"flowiseai","product":"flowise","affected":["flowise < 3.0.10"],"patched":["flowise 3.0.10"],"published":"2026-06-25","updated":"2026-09-30","sourceUpdated":"2026-09-30T16:10:00.223","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-71335","references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x7rp-qj2h-ghgw","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/flowise-session-invalidation-failure-after-password-change","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.0038,"epssPercentile":0.29489,"ingestedAt":"2026-09-30T17:13:20.777Z","slug":"CVE-2025-71335","body":"## Overview\n\nFlowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.\n\n## Affected\n\n- `flowise < 3.0.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `flowise 3.0.10`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}