Vulnerability library
Security checkNovember 14, 2025

Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmflowise-ui

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Unverified Email Change - Email as part of Credential / Unverified Account Recovery Channel Change

The application allows changing the account email address (used as a login identifier and/or password recovery address) without verifying the requester’s authority to make that change (no confirmation to the old email, no authentication step).

Recommendation

Update the flowise-ui package to the latest compatible version. Followings are version details:

  • Affected version(s): < 3.0.10
  • Patched version(s): 3.0.10

References

Could your website be exposed too?

SmartScanner can check your website for Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated November 14, 2025