FlowiseAI.Flowise.Forgot.Password.tempToken.Security.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Security Bypass Vulnerability in FlowiseAI Flowise.
The vulnerability is due to insufficient access control in forgot-password endpoint. An unauthenticated remote attacker may be able to exploit this vulnerability by sending crafted requests to the endpoint. Successful exploitation could allow an attacker to bypass authentication on the system.

affected-products-logoAffected Products

FlowiseAI Flowise prior to 3.0.5

Impact logoImpact

Security Bypass: Remote attackers can bypass security features of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/FlowiseAI

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-12-18 35.137
Modified
Default_action:pass:drop
2025-12-11 35.133
New