LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2025-71327

flowiseai · flowise

Published
CVSS9.1
Severitycritical
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71327

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71327.