Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-71335

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Версия до 3.0.10 (исключая)

EPSS

Процентиль: 24%
0.00321
Низкий

8.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 8.1
github
около 1 месяца назад

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change.

EPSS

Процентиль: 24%
0.00321
Низкий

8.1 High

CVSS3

Дефекты

CWE-613