Description
Unverified Email Change - Email as part of Credential / Unverified Account Recovery Channel Change
The application allows changing the account email address (used as a login identifier and/or password recovery address) without verifying the requester’s authority to make that change (no confirmation to the old email, no authentication step).
Recommendation
Update the flowise-ui package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.10
- Patched version(s): 3.0.10
References
Could your website be exposed too?
SmartScanner can check your website for Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change - Vulnerability
- Flowise has an MCP Security Bypass that Enables RCE - Vulnerability
- Flowise is vulnerable to arbitrary file exposure through its ReadFileTool - Vulnerability
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760


