CVE-2025-71337: Flowise - Unverified Email Change via Account Profile Endpoint
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profile endpoint without confirming the change to the original email address or re-entering the current password. By changing the recovery email, an attacker can take over the account and abuse password reset mechanisms.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flowiseto a version that resolves this vulnerability.Fixed in 3.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71337?
The severity of CVE-2025-71337 is classified as high with a score of 8.3.
How do I fix CVE-2025-71337?
To fix CVE-2025-71337, update Flowise to version 3.0.10 or later.
What systems are affected by CVE-2025-71337?
CVE-2025-71337 affects Flowise versions 3.0.7 and earlier.
Who can exploit CVE-2025-71337?
An authenticated user can exploit CVE-2025-71337 to change the account email without verification.
What impact does CVE-2025-71337 have on account security?
CVE-2025-71337 can lead to unauthorized access as the email change bypasses confirmation, compromising account recovery processes.