discovered 03 Aug 2026
CVE-2025-58434-AND-59528-POC
→ View on GitHubThe Flowise Dual CVE PoC is a proof-of-concept tool for exploiting two critical vulnerabilities (CVE-2025-58434 and CVE-2025-59528) in the Flowise platform, enabling an attacker to achieve unauthenticated account takeover followed by remote code execution in an automated manner. It leverages a flawed password reset mechanism and unsanitized user input in JavaScript execution to facilitate these exploits, making it particularly dangerous for both cloud and self-hosted deployments. The tool includes modular functionality for conducting attacks and is intended solely for authorized security research purposes.