Flowise - Session Invalidation Failure After Password Change
Vulnerability Description
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71335
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- mbiesiad
References
More from Flowise
View All →Affected Vendor
Flowise
View all reports →