CVE-2025-58434 is a critical authentication/authorization vulnerability affecting Flowise (Cloud and self-hosted) versions 3.0.5 and earlier. The application’s forgot-password endpoint returns a valid password reset temporary token (tempToken) in the API response without requiring proper authentication or verification, allowing any remote attacker to generate or obtain reset tokens for arbitrary users and immediately reset their passwords. Successful exploitation can lead to full account takeover, unauthorized access to saved flows and data, and potential lateral movement or persistence within impacted deployments.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

