Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change
- Severity:
- High
Description
Bypass of Password Confirmation - Unverified Password Change (authenticated change without current password)
An authenticated user is allowed to change their account password without supplying the current password or any additional verification.
Recommendation
Update the flowise-ui package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.10
- Patched version(s): 3.0.10
References
Related Issues
- Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials) - Vulnerability
- @udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme - CVE-2023-34245
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core - CVE-2025-53892
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core-base - CVE-2025-53892
You might also like:
- Tags:
- npm
- flowise-ui
Anything's wrong? Let us know Last updated on November 14, 2025


