Vulnerabilities/

Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)

Severity:
High

Description

Unverified Email Change - Email as part of Credential / Unverified Account Recovery Channel Change

The application allows changing the account email address (used as a login identifier and/or password recovery address) without verifying the requester’s authority to make that change (no confirmation to the old email, no authentication step).

Recommendation

Update the flowise-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-ui
Anything's wrong? Let us know Last updated on November 14, 2025