Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Flowise, a tool for building custom large language model flows, could allow unauthorized individuals to reset user passwords and take over accounts. This issue affects unpatched versions of Flowise, including both cloud-hosted and self-hosted deployments that expose the password reset feature. The concern is that an attacker could exploit this to gain access to user accounts.
- Unauthenticated password resets allow account takeover.
- Critical flaw in user account security.
- Confirm relevance and exposure of password reset.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by directly accessing the `forgot-password` endpoint without needing any credentials. This allows them to generate password reset tokens for any user, bypassing the intended secure email delivery, and subsequently take over accounts.
- No authentication required to access endpoint.
- Attacker can generate reset tokens for any user.
- Leads to complete account takeover.
Live Threat
Current exploitation, exposure, and threat context
The `forgot-password` endpoint in Flowise, when not properly secured, could allow an unauthenticated attacker to obtain a password reset token for any user. This could lead to an account takeover on both cloud and self-hosted instances that expose this API.
- User account credentials.
- Unauthenticated network access.
- Complete account takeover.
Operational Fix
Recommended remediation, mitigation, and detection steps
The `forgot-password` endpoint in Flowise versions prior to 3.0.6 is vulnerable to unauthenticated account takeover due to the leakage of password reset tokens. This impacts both the cloud service and self-hosted deployments if they expose this endpoint. The first practical step is to identify all instances of Flowise, confirm their accessibility and business criticality, and assign ownership to the appropriate team for remediation planning.
- Platform/Application owners should address this.
- Verify if password reset is exposed externally.
- Plan urgent updates or apply vendor fixes.