Authentication Bypass in Flowise Product by FlowiseAI
CVE-2025-71327

9.3CRITICAL

Key Information:

Vendor

Flowise

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2025-71327?

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint. This flaw enables unauthenticated attackers to register arbitrary user accounts, thereby gaining unauthorized access to the system's API without requiring any valid credentials. Remote attackers can exploit this vulnerability to create user accounts, allowing them full access to the API resources, potentially compromising sensitive data.

Affected Version(s)

Flowise 3.0.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ReeFSpeK
ERANV-EVA
.