{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/flowise--3.0.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-58434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flowise (\u003c 3.0.6)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Flowiseai"],"content_html":"\u003cp\u003eCVE-2025-58434 is a critical vulnerability affecting Flowiseai Flowise versions 3.0.5 and earlier. The vulnerability exists within the application's account management API, specifically the \u003ccode\u003e/api/v1/account/forgot-password\u003c/code\u003e endpoint. When an attacker sends a password reset request to this endpoint with a target user's email address, the server improperly includes a valid \u003ccode\u003etempToken\u003c/code\u003e within the JSON API response.\u003c/p\u003e\n\u003cp\u003eThis leak occurs because the application fails to adequately sanitize the response or restrict sensitive information when the request is processed. Because the \u003ccode\u003etempToken\u003c/code\u003e is returned directly to the requester, an attacker can bypass the intended password reset workflow, which should require access to the user's email inbox. This enables full, unauthenticated account takeover of any user within the target Flowise instance. The vulnerability has a CVSS v3.1 score of 9.8, and multiple functional proof-of-concept exploits have been published publicly, significantly lowering the barrier for exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs reconnaissance to identify a Flowise instance reachable over the network.\u003c/li\u003e\n\u003cli\u003eThe attacker selects a target email address associated with an account on the target Flowise instance.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an HTTP POST request to the \u003ccode\u003e/api/v1/account/forgot-password\u003c/code\u003e endpoint with the target's email address.\u003c/li\u003e\n\u003cli\u003eThe Flowise server processes the request and generates a \u003ccode\u003etempToken\u003c/code\u003e for the password reset.\u003c/li\u003e\n\u003cli\u003eThe server returns a 200 OK response containing the \u003ccode\u003etempToken\u003c/code\u003e in the response body.\u003c/li\u003e\n\u003cli\u003eThe attacker extracts the \u003ccode\u003etempToken\u003c/code\u003e from the response.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the extracted \u003ccode\u003etempToken\u003c/code\u003e to interact with the password reset completion endpoint to set a new password.\u003c/li\u003e\n\u003cli\u003eThe attacker gains full control over the compromised account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform a full account takeover of any user in the Flowise instance. This results in the loss of confidentiality and integrity of all workflows, credentials, and data accessible to that user account. Given the nature of Flowise, this likely includes exposure of API keys, sensitive data processing logs, and control over downstream automated workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all Flowise instances to version 3.0.6 or later to mitigate CVE-2025-58434.\u003c/li\u003e\n\u003cli\u003eAudit access logs for anomalous POST requests to the \u003ccode\u003e/api/v1/account/forgot-password\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for high volumes of password reset requests from single source IPs, which may indicate automated scanning or exploitation attempts.\u003c/li\u003e\n\u003cli\u003eDeploy the provided detection rule to identify and block potential exploitation attempts targeting this endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T03:48:44Z","date_published":"2026-09-03T03:48:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-flowise-cve-2025-58434/","summary":"CVE-2025-58434 is a critical vulnerability in Flowise versions prior to 3.0.6 where the password reset API leaks a temporary token, enabling unauthenticated account takeover.","title":"Unauthenticated Account Takeover in Flowise via CVE-2025-58434","url":"https://feed.craftedsignal.io/briefs/2026-09-flowise-cve-2025-58434/"}],"language":"en","title":"CraftedSignal Threat Feed - Flowise (\u003c 3.0.6)","version":"https://jsonfeed.org/version/1.1"}