Impact
Flowise before version 3.0.10 allows an authenticated user to change the account email address, which is used for both logging in and password recovery, without confirming the change or re‑entering the current password. This flaw, classified as CWE-620, lets an attacker redirect password reset links to a malicious email, effectively hijacking the account and gaining full access.
Affected Systems
The vulnerable product is Flowise, specifically versions 3.0.7 and earlier (i.e., any release prior to 3.0.10).
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity threat. Although EPSS data is not available, the vulnerability is not currently listed in the CISA KEV catalog. Exploitation only requires an authenticated session; an attacker with valid credentials can alter the recovery email, bypassing standard verification steps and enabling password reset abuse.
OpenCVE Enrichment