External risk intelligence

Flowise Password Reset Token Disclosure Leads to Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-58434

Flowise is a platform for building LLM flows that is commonly deployed as a web-based service or API endpoint. Since this vulnerability affects both cloud-hosted instances and self-hosted deployments reachable over the network, and password reset functionality is typically exposed to facilitate user access, there is a clear potential for public internet exposure.

Missing Authentication

Flowiseai Flowise

before 3.0.6

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Flowise, a tool for building custom large language model flows, could allow unauthorized individuals to reset user passwords and take over accounts. This issue affects unpatched versions of Flowise, including both cloud-hosted and self-hosted deployments that expose the password reset feature. The concern is that an attacker could exploit this to gain access to user accounts.

  • Unauthenticated password resets allow account takeover.
  • Critical flaw in user account security.
  • Confirm relevance and exposure of password reset.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by directly accessing the `forgot-password` endpoint without needing any credentials. This allows them to generate password reset tokens for any user, bypassing the intended secure email delivery, and subsequently take over accounts.

  • No authentication required to access endpoint.
  • Attacker can generate reset tokens for any user.
  • Leads to complete account takeover.

Live Threat

Current exploitation, exposure, and threat context

The `forgot-password` endpoint in Flowise, when not properly secured, could allow an unauthenticated attacker to obtain a password reset token for any user. This could lead to an account takeover on both cloud and self-hosted instances that expose this API.

  • User account credentials.
  • Unauthenticated network access.
  • Complete account takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

The `forgot-password` endpoint in Flowise versions prior to 3.0.6 is vulnerable to unauthenticated account takeover due to the leakage of password reset tokens. This impacts both the cloud service and self-hosted deployments if they expose this endpoint. The first practical step is to identify all instances of Flowise, confirm their accessibility and business criticality, and assign ownership to the appropriate team for remediation planning.

  • Platform/Application owners should address this.
  • Verify if password reset is exposed externally.
  • Plan urgent updates or apply vendor fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a platform that provides a visual, drag-and-drop interface for developers to build and customize workflows for large language models. It is frequently deployed as a web service or API to manage these model integrations, and it serves as the underlying framework for both cloud-hosted environments and private, self-hosted infrastructure.

What does CWE-306 mean for CVE-2025-58434?

CWE-306 refers to a Missing Authentication for Critical Function weakness. In the context of CVE-2025-58434, this means a vital security feature—the password reset process—is accessible without verifying the user's identity. Because the software fails to require authentication, it allows an unauthorized person to interact with the system as if they were a legitimate user.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a request to the application's forgotten password endpoint. Because the system lacks proper checks, it will return a sensitive password reset token directly in the API response. Merely interacting with this endpoint is sufficient; no prior knowledge of an account, login credentials, or bypassing email-based verification systems is required to retrieve a valid token.

Is my Flowise instance relevant to this threat?

According to Halo Surface Signal, this vulnerability is highly relevant if your Flowise deployment is reachable over the network. Because the password reset functionality is a standard feature of the application, any instance exposed to the public internet is potentially at risk of being targeted to facilitate unauthorized account takeovers.

Do I need to update my software immediately?

Yes, identifying and updating affected versions is the primary response. You should confirm if your deployment is running a version prior to 3.0.6. If it is, the immediate priority is to plan for an update to a secure version that resolves the API disclosure flaw, while ensuring that the password reset process is restricted to secure, email-based delivery channels.

References