Vulnerability Description
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profile endpoint without confirming the change to the original email address or re-entering the current password. By changing the recovery email, an attacker can take over the account and abuse password reset mechanisms.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flowiseai | Flowise | <= 3.0.7 |
Related Weaknesses (CWE)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x39m-3393-3qp4ExploitThird Party Advisory
- https://www.vulncheck.com/advisories/flowise-unverified-email-change-via-accountThird Party Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x39m-3393-3qp4ExploitThird Party Advisory
FAQ
What is CVE-2025-71337?
CVE-2025-71337 is a vulnerability with a CVSS score of 8.3 (HIGH). Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier an...
How severe is CVE-2025-71337?
CVE-2025-71337 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71337?
Check the references section above for vendor advisories and patch information. Affected products include: Flowiseai Flowise.