
This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users without authentication process in flowise version 3.0.5 and lower due to token leakage.
This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users without authentication process in flowise version 3.0.5 and lower due to token leakage.
To run the exploit, use the CVE-2025-58434-PoC.py script and provide the target url, email address of the target whose password you wish to change, and the password you wish to replace the old password with. If ran succesfully, the password of the victim is changed to the provided password and the attacker can then login to the victims account.
Python3 should be installed on the attacker machine.
python3 CVE-2025-58434-PoC.py -u <target_url> -e <target_email> -p <new_password>
This Proof of Concept (PoC) is for educational and research purposes only. It is intended to help security researchers and administrators understand and mitigate the CVE-2025-58434 vulnerability.
The author takes no responsibility for any unauthorized or malicious use of this code. Use this tool only on systems you own or have explicit permission to test. By using this code, you agree to take full responsibility for your actions.