VDB
CNVD-2025-21415
CNVD-2025-21415
PUBLISHED
Flowise是FlowiseAI开源的一个用于轻松构建LLM应用程序的工具。 Flowise 3.0.5及之前版本存在访问控制错误漏洞,该漏洞源于forgot-password端点未经验证返回密码重置令牌,攻击者可利用该漏洞导致账户接管。
Timeline
- Sep 12, 2025 CVE Published
Tip. Type any identifier and press Enter to open its detail page. Hit ⌘K from anywhere to focus the bar.
Open the full search in the app →Flowise是FlowiseAI开源的一个用于轻松构建LLM应用程序的工具。 Flowise 3.0.5及之前版本存在访问控制错误漏洞,该漏洞源于forgot-password端点未经验证返回密码重置令牌,攻击者可利用该漏洞导致账户接管。