#VU125534 Insufficient Session Expiration in Flowise
Published: April 9, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote user to retain unauthorized access to the application after a password change.
The vulnerability exists due to insufficient session expiration in session management when processing password changes. A remote user can continue using an existing active session token to retain unauthorized access to the application after a password change.
The issue affects other active sessions or session tokens that were established before the password change.