---
id: CVE-2025-71327
title: >-
  Flowise contains an authentication bypass vulnerability in the unprotected
  /api/v1/account/register endpoint that allows unauthenticated attackers to
  create user accounts
summary: >-
  Flowise contains an authentication bypass vulnerability in the unprotected
  /api/v1/account/register endpoint that allows unauthenticated attackers to
  create user accounts. Remote attackers can exploit this endpoint to register
  arbitrary …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-306
vendor: flowiseai
product: flowise
affected:
  - flowise = 3.0.1
published: '2026-06-25'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71327'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-v5w9-prxf-w882
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-authentication-bypass-via-unprotected-registration-endpoint
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-v5w9-prxf-w882
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00675
epssPercentile: 0.50354
ingestedAt: '2026-09-30T17:13:20.775Z'
---

## Overview

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.

## Affected

- `flowise = 3.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
