---
id: CVE-2025-71328
title: Flowise before 3.0.10 contains an unverified password change vulnerability
summary: >-
  Flowise before 3.0.10 contains an unverified password change vulnerability. An
  authenticated user can change their account password through the account
  settings (Security) section without supplying the current password or any
  additional …
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-620
vendor: flowiseai
product: flowise
affected:
  - flowise < 3.0.10
patched:
  - flowise 3.0.10
published: '2026-06-25'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71328'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fjh6-8679-9pch
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-unverified-password-change-via-account-settings
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fjh6-8679-9pch
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00473
epssPercentile: 0.38543
ingestedAt: '2026-09-30T17:13:20.776Z'
---

## Overview

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session.

## Affected

- `flowise < 3.0.10`

## Remediation

Upgrade past the affected range:

- `flowise 3.0.10`
