CVE-2025-71327: Flowise - Authentication Bypass via Unprotected Registration Endpoint
Published Jun 25, 2026
·Updated
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.
Affected Software
2 affected components
Flowise
FlowiseAI Flowise=3.0.1
Event History
Jun 25, 2026
CVE Published
via MITRE·09:41 PM
Data Sourced
via MITRE·09:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71327?
CVE-2025-71327 has a critical severity rating of 9.3.
2
How do I fix CVE-2025-71327?
To fix CVE-2025-71327, implement authentication controls to secure the /api/v1/account/register endpoint.
3
What does CVE-2025-71327 allow an attacker to do?
CVE-2025-71327 allows unauthenticated attackers to create user accounts and gain full API access.
4
Which software is affected by CVE-2025-71327?
CVE-2025-71327 affects the Flowise software.
5
What type of vulnerability is CVE-2025-71327?
CVE-2025-71327 is an authentication bypass vulnerability.