CVE-2025-71327

Source
https://cve.org/CVERecord?id=CVE-2025-71327
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71327.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-71327
Aliases
Published
2026-06-25T21:41:03Z
Modified
2026-08-12T03:51:38Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Flowise - Authentication Bypass via Unprotected Registration Endpoint
Details

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71327.json"
}
References

Affected packages

Git / github.com/flowiseai/flowise

Affected ranges

Type
GIT
Repo
https://github.com/flowiseai/flowise
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:flowiseai:flowise:3.0.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.0.1"
        },
        {
            "last_affected": "3.0.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

3.*
3.0.1
flowise-components@3.*
flowise-components@3.0.1
flowise-ui@3.*
flowise-ui@3.0.1
flowise@3.*
flowise@3.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71327.json"