CVE-2025-71327Disclosure(flowiseai / flowise)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch flowiseai flowise systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
flowise

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-26: 106-26
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Flowise unauthenticated account creation via exposed registration API (CVE-2025-71327) Flowise exposes an unprotected /api/v1/account/register endpoint in its API layer that allows anyone to register new user accounts without prior authentication. The issue stems from missing access control/improper authentication enforcement on the registration route, effectively creating an authentication bypass. An unauthenticated attacker can remotely hit the endpoint over HTTP to create an account, then log in normally and operate as a valid user without any legitimate credentials. If exploited, this results in full API access under attacker-controlled accounts, enabling unauthorized data access and potential takeover of workflows, integrations, and connected resources. 👉 Affected: flowise (version range not specified) | Upgrade to vendor-fixed release (not specified)

    Post summary

    The post discloses a critical unauthenticated account creation flaw in Flowise (CVE‑2025‑71327), outlines its impact, and recommends upgrading to the vendor‑fixed release, but provides no PoC, exploit code, or evidence of active exploitation.

    0000072
    231 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise3.0.1--

Explore more