CVE-2025-58434PoC(flowiseai / flowise)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073846433a596590d3d9c863 in version 3.0.6 secures password reset endpoints. Several recommended remediation steps are available. Do not return reset tokens or sensitive account details in API responses. Tokens must only be delivered securely via the registered email channel. Ensure `forgot-password` responds with a generic success message regardless of input, to avoid user enumeration. Require strong validation of the `tempToken` (e.g., single-use, short expiry, tied to request origin, validated against email delivery). Apply the same fixes to both cloud and self-hosted/local deployments. Log and monitor password reset requests for suspicious activity. Consider multi-factor verification for sensitive accounts.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-15); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-03-06: 1Mentions · 2026-04-08: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-05-09: 1Mentions · 2026-05-14: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-15: 2PoC Mentioned / Linked · 2026-05-09: 1Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-05-09: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-15: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 2Technical Details · 2026-05-09: 103-0604-0804-1404-1505-0905-1408-27
Signal classification4 categories
PoC
450.0%
General
225.0%
Disclosure
112.5%
Active Exploitation
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-04-081
Active Exploitation1
2026-04-141
PoC1
2026-04-152
PoC2
2026-05-091
PoC1
2026-05-141
General1
2026-08-271
General1
Full discourse8 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    The text consists solely of a list of CVE identifiers, providing no further context or details.

    2176862729382.1K
    3.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2025-58434 and CVE-2025-59528: Flowise Dual CVE PoC GitHub: https://github.com/kartik2005221/CVE-2025-58434-AND-59528-POC The two vulnerabilities chain naturally: CVE-2025-58434 provides unauthenticated account takeover, which satisfies the authentication requirement for CVE-2025-59528, achieving unauthenticated RCE in a single automated run.

    Post summary

    The post announces and links to a proof‑of‑concept that chains CVE‑2025‑58434 and CVE‑2025‑59528 for an automated unauthenticated remote code execution.

    3170834113.6K
    221.0K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The content lists a series of CVE identifiers without providing additional information on exploitation, patches, or technical details.

    30124138.4K
    4.0K followersView on X
  • Daeras@0xDaeras
    PoC

    Hi 👋 Recently published two CVE PoCs on GitHub: - CVE-2024-51482 → ZoneMinder auth time-based blind SQL injection - CVE-2025-58434 + CVE-2025-59528 → FlowiseAI ATO + RCE chain Available here: https://github.com/0xDaeras ⚠️ For educational and authorized security research only.

    Post summary

    The message announces publicly available Proof‑of‑Concept code for two CVEs on GitHub, describing the nature of the vulnerabilities but providing no evidence of active exploitation, patches, or debunking.

    000301.1K
    57 followersView on X
  • VulnTracker@vuln_tracker
    PoC

    this is a good example of why chained CVEs are scarier than the individual scores suggest CVE-2025-58434 (unauth takeover) + CVE-2025-59528 (RCE via MCP node) = full compromise, no credentials needed to start. PoC is already public. if you're running Flowise in any AI pipeline, go check. http://vulntracker.io

    Post summary

    The tweet announces that two chained CVEs can lead to a full compromise without credentials, notes that a publicly available PoC exists for Flowise, and provides a link to the PoC.

    00001313
    538 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 #Flowise, Authentication Bypass, #CVE-2025-58434 (High) https://dailycve.com/flowise-authentication-bypass-cve-2025-58434-high/

    Post summary

    A new authentication bypass vulnerability (CVE‑2025‑58434) in Flowise has been disclosed as high severity, but no PoC, exploit details, or mitigation information are provided in the tweet.

    10000121
    164 followersView on X
  • Grok@grok
    PoC

    这个是Flowise(开源AI流程构建工具)的双CVE PoC公告。 CVE-2025-58434:无认证账户接管。forgot-password接口直接返回密码重置token,攻击者可重置任意用户密码,实现ATO。 CVE-2025-59528:CustomMCP节点RCE。用户输入的mcpServerConfig未过滤,直接传给Function()执行任意JS代码(可shell)。 二者链式利用:先ATO获认证,再RCE。影响自托管版(云版仅第一漏洞),CVSS 9.8/10.0,已有野外利用。 PoC在GitHub自动化实现,推荐立即升级到3.0.6+,否则服务器易被控。

    Post summary

    The post announces a proof‑of‑concept for two critical CVEs in Flowise, details the exploitation mechanisms, reports real‑world use, and urges an urgent upgrade to mitigate the vulnerabilities.

    00000177
    8.7M followersView on X
  • Hephaestvs@Vulcanux_
    Active Exploitation

    csirt_it: ‼️ #Exploited: rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2025-59528, relativa al prodotto #Flowise Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/flowise-rilevato-sfruttamento-in-rete-della-cve-2025-58434 ⚠️ Importante mantenere aggiornati i sistemi https://x.com/csirt_it/status/2041848593695358988/photo/1

    Post summary

    The tweet announces that CVE-2025-59528 is currently being exploited in the wild for Remote Code Execution on Flowise, and urges users to keep their systems updated.

    00000294
    605 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more