Insufficient Session Expiration in Flowise - #VU125534
Published: April 9, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote user to retain unauthorized access to the application after a password change.
The vulnerability exists due to insufficient session expiration in session management when processing password changes. A remote user can continue using an existing active session token to retain unauthorized access to the application after a password change.
The issue affects other active sessions or session tokens that were established before the password change.