Flowise through version 3.0.5 exposes a valid temporary password-reset token in the response generated by its password-recovery workflow. An unauthenticated requester can initiate recovery for an arbitrary registered account, obtain the returned token, and use it to set a new password without demonstrating control of the account's registered email address. The flaw affects both Flowise cloud and self-hosted deployments exposing the affected API.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
18 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This two-file repository contains a Python proof of concept and supporting README for CVE-2025-58434 affecting Flowise AI versions through 3.0.5. The standalone script accepts a target base URL, account email, and optional replacement password. It posts a deliberately invalid login to /api/v1/auth/login to determine whether the email likely exists, calls /api/v1/account/forgot-password, extracts user.tempToken from the unauthenticated JSON response, then posts that token with a new password to /api/v1/account/reset-password. Successful execution changes the target account password and enables account takeover. The code uses Python requests and argparse; no exploit framework is involved. The README documents affected/fixed versions, request flow, dependencies, and remediation. No fixed host, IP address, or domain is embedded: the target base URL is supplied by the operator at runtime.
This five-file standalone Python repository contains two exploit scripts, a README, license, and gitignore. flowise_ato_foothold.py implements a complete web attack chain against Flowise: it requests a password-reset token via CVE-2025-58434, resets the hardcoded victim account password, logs in, obtains an API key, then submits a crafted mcpServerConfig value to CustomMCP. The configuration is evaluated as server-side JavaScript and invokes Node.js child_process.exec to launch a FIFO/netcat reverse shell. flowise_customMCP_rce.py is a smaller authenticated variant that takes an arbitrary command and API key, base64-wraps the command for /bin/sh, and sends the same JavaScript-injection request. Target addressing is templated through TARGET_IP and a flowise.target.tld Host header. This is active exploitation code, not merely a vulnerability check.
This repository is a minimal two-file proof-of-concept exploit for CVE-2025-58434 affecting FlowiseAI. The README only names the issue, while exploit.py contains the full exploit logic. The Python script takes two command-line arguments: a target base URL and a victim email address. It builds two FlowiseAI API paths under the supplied target: /api/v1/account/forgot-password and /api/v1/account/reset-password. The exploit first sends a forgot-password request for the supplied email, parses the JSON response, and extracts user.tempToken. It then immediately submits that token back to the reset-password endpoint along with a hardcoded replacement password, "Fl0w1s3PoC", thereby taking over the account if the target is vulnerable. The script prints the recovered reset token and the new credentials on success. There is no detection-only logic, no stealth, no brute force, and no payload customization beyond changing the target and email arguments or editing the hardcoded password in code. This is an operational but basic web exploit demonstrating account takeover via abuse of an insecure password reset/authentication flow.
This repository is a small standalone Python proof-of-concept for CVE-2025-58434 affecting Flowise. It contains two files: a single exploit script (CVE-2025-58434-PoC.py) and a README with usage instructions. The script uses argparse for CLI input, requests for HTTP communication, and termcolor for status output. The exploit logic is straightforward and operational: it first sends a POST request to /api/v1/account/forgot-password with the victim's email address, then parses the JSON response and extracts user.tempToken. It immediately sends a second POST request to /api/v1/account/reset-password with the victim email, leaked tempToken, and an attacker-chosen new password. If both requests succeed, the victim's password is changed, resulting in account takeover. There is no shellcode, RCE, persistence, or post-exploitation logic; the capability is limited to unauthorized password reset via exposed web API endpoints. The script is not part of a larger exploit framework and does not include detection-only behavior. Its structure and purpose are clear: automate exploitation of a password reset token leakage flaw in vulnerable Flowise instances.
This repository is a standalone Python exploit lab and proof-of-concept for chaining two Flowise vulnerabilities: CVE-2025-58434 (password reset token disclosure leading to account takeover) and CVE-2025-59528 (authenticated JavaScript injection/RCE in the CustomMCP node). The main exploit logic is in exploit.py, which uses requests, argparse, and multiple modes: check, ato-mode, login-mode, rce-mode, and full-mode. Based on the README and visible code, the exploit initializes an HTTP session, optionally checks whether the target appears vulnerable, performs the forgot-password/reset-password flow to seize an account, logs in to obtain authenticated state, and then sends a malicious payload to the CustomMCP load-method endpoint to execute commands on the server. It supports either a custom command or a reverse-shell style command using attacker-provided lhost/lport. Repository structure is small and purposeful: exploit.py is the operational PoC; README.md documents the CVE chain, attack flow, usage, and detection ideas; requirements.txt only requires requests; docker-compose.yml plus docker/Dockerfile and docker/entrypoint.sh create a reproducible vulnerable lab using flowiseai/flowise:3.0.5 and Mailpit. The entrypoint script waits for Flowise to start and attempts to create admin and secondary users through several setup/register endpoints, making the lab easy to test. The exploit is not merely a detector: it contains active exploitation workflow and authenticated RCE capability. It is best classified as OPERATIONAL rather than WEAPONIZED because it is a standalone PoC with hardcoded/basic payload behavior rather than a reusable exploitation framework.
Repository is a standalone Python exploit/lab package for chaining two Flowise vulnerabilities: CVE-2025-58434 (password reset token exposure leading to account takeover) and CVE-2025-59528 (authenticated RCE through unsafe JavaScript evaluation in the CustomMCP node). The main exploit logic is in exploit.py, a CLI tool using requests with multiple modes: check, ato-mode, login-mode, rce-mode, and full-mode. Based on the README and visible code, it initializes an HTTP session, optionally checks vulnerability status, performs password reset abuse to set a new password, logs in to obtain cookies/token, and then sends an authenticated RCE request to the CustomMCP endpoint. It also supports direct token use, custom command execution, and reverse-shell parameters via --lhost/--lport. Repository structure is small and purposeful: exploit.py is the primary entry point; requirements.txt only depends on requests; README.md documents the CVE chain, attack flow, vulnerable endpoint, and usage; docker-compose.yml plus docker/Dockerfile and docker/entrypoint.sh create a reproducible Flowise 3.0.5 lab with Mailpit and bootstrap users. The lab container exposes Flowise on port 3000 and Mailpit on 8025, stores Flowise data under /root/.flowise, and uses local API calls to create accounts through several possible setup/register endpoints. This is not merely a detector: it contains exploitation workflow and authenticated post-auth command execution capability, making it an operational PoC rather than a simple scanner. No evidence suggests it belongs to a major exploit framework. The exploit targets web/network attack surfaces and fingerprints several Flowise API routes that defenders can monitor, especially forgot-password, reset-password, auth/login, and node-load-method/customMCP.
This repository is a small standalone Python proof-of-concept for CVE-2025-58434. It contains only two files: a README describing the issue and usage, and a single executable script, poc.py. The script is interactive and prompts the operator for a target machine URL or IP, optionally a scheme if a bare host is provided, a victim email address, and a new password. The exploit logic is straightforward: it sends a POST request with JSON to /api/v1/account/forgot-password, prints the HTTP response similarly to curl -i, parses the JSON body, and extracts user.tempToken if present. If a tempToken is found, it sends a second POST request to /api/v1/account/reset-password with the email, extracted tempToken, and operator-supplied password. Successful exploitation would allow the operator to reset the target account password. The code uses only Python standard library modules (json, sys, urllib.error, urllib.request), so it is easy to run and does not require external dependencies. This is an actual exploit rather than a detector because it performs the full password-reset abuse flow and attempts account takeover by changing the password. It is best classified as OPERATIONAL: it includes a working exploit path and payload data, but it is a simple standalone PoC rather than a customizable framework module. Notable implementation detail: in the second request success path, the script mistakenly reads from the first response object instead of response2 when assigning body, but this does not change the exploit's core purpose or the targeted endpoints.
This repository is a small standalone Python exploit for CVE-2025-58434 affecting Flowise. It contains three files: a single Python exploit script, a README describing the issue and usage, and a LICENSE. The exploit is not part of a larger framework. The main script, CVE-2025-58434-PasswordReset.py, uses argparse for CLI input and requests for HTTP interaction. Its workflow is straightforward: it accepts a base URL, victim email, and attacker-chosen new password; sends a POST request with JSON to the Flowise forgot-password API; parses the JSON response for user.tempToken; and, if present, sends a second POST request to the reset-password API with the victim email, extracted tempToken, and new password. Successful execution results in the victim password being changed, enabling account takeover. The exploit’s core capability is unauthenticated password reset abuse. It does not deliver shellcode or remote code execution; instead, it abuses broken authentication/authorization logic in the password reset flow. The attack surface is the web API of a Flowise instance. The key fingerprintable targets are the two API paths /api/v1/account/forgot-password and /api/v1/account/reset-password. Repository structure is minimal and purpose-built: one operational exploit script plus documentation. The README states the vulnerability affects Flowise Cloud and self-hosted deployments version 3.0.5 and earlier, and explains that the forgot-password endpoint improperly returns a valid tempToken that can be immediately reused without email verification or authentication.
This repository is a small standalone Python exploit for a Flowise exploit chain combining CVE-2025-58434 and CVE-2025-59528. The repository contains only two files: a minimal README naming the CVE and a single executable script, exploit.py, which is the full entry point and operational logic. The script supports two modes. In full-chain mode, it performs account takeover by calling the forgot-password API and extracting a leaked tempToken from the JSON response, then uses that token to reset the victim account password. Because the author notes a Flowise 3.0.5 login/API quirk, the script then requires a manual step: the operator logs into the web UI with the reset password, visits the API key page, and pastes the API key back into the script. In RCE-only mode, the operator can skip the takeover steps and provide an API key directly. After obtaining an API key, the exploit targets /api/v1/node-load-method/customMCP. It crafts a malicious JavaScript object expression for the mcpServerConfig input that invokes process.mainModule.require("child_process").execSync(...), enabling arbitrary command execution in the Flowise server context. The operator can either run a supplied command or generate a hardcoded mkfifo/netcat reverse shell payload. The script also checks /api/v1/version and warns that versions above 3.0.5 may be patched, explicitly noting a fix in 3.0.6. Overall, this is a real exploit rather than a detector. It is operational but not heavily weaponized: it includes a working payload and exploit chain, but relies on manual API key extraction in the default ATO flow and uses a basic hardcoded reverse shell.
This repository is a small, focused proof-of-concept exploit for CVE-2025-58434 affecting Flowise AI versions 3.0.5 and earlier. It contains two files: a Python exploit script (CVE-2025-58434_POC.py) and a README describing the vulnerability, affected endpoints, usage, and remediation. The exploit script uses the requests and argparse libraries and is structured around three helper functions plus a main entry point. First, checkUser() sends a POST request to /api/v1/auth/login with a dummy password to determine whether the supplied email exists, relying on the distinct response message "Incorrect Email or Password" for enumeration. Next, forgotPassword() sends a POST request to /api/v1/account/forgot-password and extracts user.tempToken directly from the JSON response. Finally, resetPassword() sends a POST request to /api/v1/account/reset-password with the victim email, leaked tempToken, and attacker-chosen password to complete the password reset. The exploit's main capability is unauthenticated password reset leading to account takeover. A secondary capability is user/email enumeration. There is no shellcode, RCE payload, persistence, or post-exploitation logic; the payload is a sequence of crafted HTTP POST requests against vulnerable Flowise API endpoints. Because it performs a real state-changing action with a configurable password but remains a simple standalone script, the maturity is best classified as OPERATIONAL. Fingerprintable targets/endpoints are the three Flowise API paths: /api/v1/auth/login, /api/v1/account/forgot-password, and /api/v1/account/reset-password. The script expects a user-supplied base URL for the target Flowise instance and combines it with these paths. Overall, the repository's purpose is to demonstrate and validate the broken authentication/password reset flaw in vulnerable Flowise AI deployments.
Small two-file repository containing a single Python exploit script (RCE.py) and a brief README. The script is a chained exploit for Flowise that first performs reconnaissance by querying /api/v1/version, then abuses the forgot-password workflow to obtain a tempToken for a supplied victim email, resets that account's password, logs in with the new credentials, and finally exploits the Custom MCP node endpoint to achieve remote code execution. The RCE stage injects JavaScript into the mcpServerConfig field, uses Node.js process.mainModule.require('child_process') to invoke execSync, and runs a BusyBox netcat reverse shell command to connect back to an attacker-specified host and port. The exploit uses Python requests.Session for stateful HTTP interaction and argparse for CLI parameters. Repository purpose is clearly offensive exploitation rather than detection: it automates account takeover plus authenticated RCE against vulnerable Flowise instances.
Repository is a small standalone Python exploit PoC for chaining two Flowise vulnerabilities: CVE-2025-58434 (password reset token disclosure leading to account takeover) and CVE-2025-59528 (authenticated RCE through CustomMCP unsafe JavaScript evaluation). Structure is minimal: README.md documents the vulnerabilities, attack chain, usage, and remediation; DISCLAIMER.md contains legal language; requirements.txt lists the single dependency (requests); and main.py implements the exploit logic. The main capability is automated end-to-end exploitation. In default mode, main.py runs the full chain: request forgot-password for a supplied email, extract the leaked tempToken, reset the victim password, authenticate, collect cookies/session material, and then send a malicious request to the CustomMCP load-method endpoint to execute attacker-controlled code. The tool also supports modular operation for ATO-only, login-only, and RCE-only stages. Payload behavior is operational rather than framework-grade: it includes a built-in reverse shell generator using mkfifo + /bin/sh + nc, and also supports custom command execution. Fingerprintable targets in the exploit are Flowise API paths /api/v1/account/forgot-password, /api/v1/account/reset-password, /auth/login, and /api/v1/node-load-method/customMCP, plus the required x-request-from: internal header and authenticated cookies token, refreshToken, and connect.sid. The default payload touches local path /tmp/f and invokes /bin/sh and nc for shell access. Overall, this is a real exploit repository, not a detector: it is a single-file Python PoC intended to weaponize a natural vulnerability chain from unauthenticated account takeover to self-hosted Flowise remote code execution.
This repository contains a small two-stage exploit chain for the Hack The Box 'Silentium' target. The structure is simple: one Bash script for user enumeration, one Python script for remote code execution, a README describing the workflow, and a large username wordlist. CVE-2025-58434.sh iterates through users.txt, builds email addresses in the form <user>@silentium.htb, and POSTs JSON to http://staging.silentium.htb/api/v1/account/forgot-password. It treats any response other than HTTP 404 as evidence of a potentially valid account, making it an information-disclosure/user-enumeration exploit rather than mere detection. CVE-2025-59528.py is the main RCE component: it accepts target host, Bearer token, listener host, and listener port; sends a POST request to /api/v1/node-load-method/customMCP; and injects JavaScript into the mcpServerConfig field. The injected code uses process.mainModule.require('child_process').execSync(...) to execute a Bash reverse shell command on the target. The payload creates a named pipe at /tmp/f and uses nc to connect back to the attacker. Overall, the repository is operational exploit code rather than a framework module: it automates reconnaissance and exploitation against a vulnerable web/API application, with the final outcome being authenticated remote code execution and a reverse shell.
This repository is a small standalone Python proof-of-concept for CVE-2025-58434 affecting Flowise. It contains one executable script (CVE-2025-58434.py) plus README and disclaimer documentation. The Python script uses the requests library and implements a two-stage exploit chain against Flowise account recovery APIs. In Stage 1, it sends a POST request to /api/v1/account/forgot-password with a victim email and parses the JSON response for tempToken and tokenExpiry, demonstrating that the application discloses a valid password reset token without authentication. The script also displays leaked account fields from the response, indicating possible exposure of additional sensitive user metadata. In Stage 2, when invoked with --reset, it submits the leaked token, victim email, and an attacker-chosen password to /api/v1/account/reset-password to change the account password and complete account takeover. The exploit is operational rather than a simple detector because it includes the full password reset action, but it is still a basic standalone PoC rather than a framework-integrated or highly customizable weaponized tool. The primary attack surface is web/network accessible Flowise instances, including cloud.flowiseai.com and self-hosted deployments. No persistence, malware delivery, or post-exploitation automation is present; the exploit’s purpose is credential reset and account takeover via insecure password recovery token disclosure.
This repository is a minimal proof-of-concept exploit consisting of two files: a text file containing two curl commands and a short README instructing the user to replace example.com with the target. There is no standalone program or framework integration; the exploit is a manual HTTP request sequence. The exploit targets a web application's password reset workflow associated with CVE-2025-58434. The first request sends a POST to `/api/v1/account/forgot-password` with a JSON body containing a victim email address. The second request sends a POST to `/api/v1/account/reset-password` with the same email, a temporary reset token, and a new password. Both requests include the nonstandard header `x-request-from: internal`, which strongly suggests the vulnerability is an authorization or trust-boundary bypass where the server incorrectly trusts a client-controlled header to identify internal requests. Main capability: account takeover via password reset abuse. The PoC does not deliver code execution or a shell; instead, it enables unauthorized credential change for a chosen account, demonstrated against `admin@example.com`. The comment `# Extract tempToken` indicates the operator must retrieve the reset token from the application's response or another exposed channel before issuing the second request. Repository structure is extremely small and purpose-built: `CVE-2025-58434-PoC.txt` is the only exploit artifact, and `README.md` provides a single usage note. Because the exploit includes a concrete password-reset payload and a hardcoded example token/password but no automation beyond curl commands, its maturity is best classified as OPERATIONAL rather than weaponized.
This repository is a small standalone exploit repo containing two files: a README describing the exploit chain and one Python script, flowise_chain.py, which is the operational entry point. The script targets Flowise <= 3.0.5 and chains two vulnerabilities: CVE-2025-58434 for unauthenticated account takeover and CVE-2025-59528 for authenticated remote code execution. The exploit flow is straightforward: it optionally checks the target version via /api/v1/version, abuses /api/v1/account/forgot-password to obtain a password reset tempToken for a known email address, then submits that token to /api/v1/account/reset-password to set a new password. Because the author notes a Flowise 3.0.5 login quirk, the script does not automate API-key extraction after reset; instead it instructs the operator to log into /login manually and copy the API key from /apikey. If an API key is already known, the account takeover stage can be skipped entirely. For code execution, the script sends a crafted JSON request to /api/v1/node-load-method/customMCP with a Bearer API key. The payload injects JavaScript into the CustomMCP node configuration and uses process.mainModule.require("child_process").execSync(...) to run arbitrary OS commands. The operator can either run a single command (default: id) or generate a hardcoded mkfifo/netcat reverse shell that uses /tmp/f and /bin/sh and connects back to an attacker-supplied LHOST:LPORT. Overall, this is a real exploit rather than a detector. It is not part of a common exploitation framework. Its capabilities are account takeover, password reset abuse, authenticated API abuse, arbitrary command execution, and reverse shell delivery. The implementation is operational but basic: payloads are hardcoded and interaction is partly manual, especially for API key retrieval.
This repository is a small standalone Python exploit for Flowise versions earlier than 3.0.5. It contains only two files: a minimal README listing CVE-2025-58434 and CVE-2025-59528, and the main exploit script flowise-rce-3.0.5.py. The script uses argparse for four required inputs: target URL, victim email, new password, and command to execute. Its workflow is straightforward: first it attempts login with the supplied credentials; if login fails, it abuses the password reset flow by calling /api/v1/account/forgot-password, extracting a tempToken from the JSON response, and submitting /api/v1/account/reset-password to set a new password for the target account. After successful authentication, it sends a malicious payload to /api/v1/node-load-method/customMCP with loadMethod=listActions and a crafted mcpServerConfig value containing JavaScript. That JavaScript imports Node's child_process module via process.mainModule.require and runs the attacker-supplied command with execSync. If the first RCE request returns 401, the script retries after adding the x-request-from: internal header. Overall, the exploit provides chained account takeover plus authenticated remote code execution against vulnerable Flowise API endpoints.
This repository is a small standalone exploit repo with 2 files: a README describing the exploit chain and one Python script, flowise_chain.py, which is the operational entry point. The script targets Flowise <= 3.0.5 and chains two vulnerabilities: CVE-2025-58434 for unauthenticated account takeover and CVE-2025-59528 for authenticated remote code execution. Repository structure is simple and purpose-built. README.md documents the affected versions, prerequisites, and example usage. flowise_chain.py implements the full workflow: version check, password-reset token theft, password reset, manual API key acquisition, and final RCE trigger. Main capabilities: 1. Version probing via GET /api/v1/version. 2. Unauthenticated password reset token disclosure by POSTing to /api/v1/account/forgot-password with a known victim email and extracting user.tempToken from the JSON response. 3. Password reset by POSTing the leaked token to /api/v1/account/reset-password. 4. Manual operator-assisted login to /login and API key collection from /apikey due to a documented Flowise 3.0.5 authentication quirk. 5. Authenticated RCE by POSTing to /api/v1/node-load-method/customMCP with a malicious JavaScript expression in inputs.mcpServerConfig. The injected code uses process.mainModule.require("child_process").execSync(...) to run arbitrary commands. 6. Optional reverse shell generation using a hardcoded mkfifo + nc payload that connects back to an operator-supplied LHOST:LPORT. The exploit is not just a detector; it performs real state-changing actions on the target and can yield command execution. It is operational rather than weaponized because it includes a working payload and exploit chain, but customization is limited and it is not embedded in a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability affecting Flowise up to and including version 3.0.5. The content indicates a Metasploit auxiliary module was added to detect and exploit it, making it significant for offensive security and defender prioritization.
A Flowise account-takeover vulnerability caused by disclosure of a password-reset token in the password-reset API response.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.