Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)
- Severity:
- High
Description
Unverified Email Change - Email as part of Credential / Unverified Account Recovery Channel Change
The application allows changing the account email address (used as a login identifier and/or password recovery address) without verifying the requester’s authority to make that change (no confirmation to the old email, no authentication step).
Recommendation
Update the flowise-ui package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.10
- Patched version(s): 3.0.10
References
Related Issues
- Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change - Vulnerability
- Flowise has an MCP Security Bypass that Enables RCE - Vulnerability
- Flowise is vulnerable to arbitrary file exposure through its ReadFileTool - Vulnerability
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
You might also like:
- Tags:
- npm
- flowise-ui
Anything's wrong? Let us know Last updated on November 14, 2025


