Vulnerabilities/

Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change

Severity:
High

Description

Bypass of Password Confirmation - Unverified Password Change (authenticated change without current password)

An authenticated user is allowed to change their account password without supplying the current password or any additional verification.

Recommendation

Update the flowise-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-ui
Anything's wrong? Let us know Last updated on November 14, 2025