Vulnerability DatabaseGHSA-fjh6-8679-9pch

GHSA-fjh6-8679-9pch
JavaScript vulnerability analysis and mitigation

Summary

Bypass of Password Confirmation - Unverified Password Change (authenticated change without current password) An authenticated user is allowed to change their account password without supplying the current password or any additional verification. The application does not verify the actor’s authority to perform that credential change (no current-password check, no authorization enforcement). An attacker who is merely authenticated (or who can trick or coerce an authenticated session) can set a new password and gain control of the account. (ATO - Account Takeover)

Details

Occurence - code: https://github.com/FlowiseAI/Flowise/blob/main/packages/ui/src/views/account/index.jsx#L278 Remote and physical scenarios can be considered.

PoC

Repro steps:

  1. As logged in user https://cloud.flowiseai.com/account scroll down to 'Security' section
  2. Change password to the new password
  3. Notice Unverified Password Change (authenticated change without current password) POC: Password changed, and notice "Password updated" message. Screenshot: secpw

Impact

Full account takeover (ATO) of affected accounts (loss of confidentiality and integrity of account data). User account recovery mechanisms (password reset flows tied to email) can be bypassed or abused if combined with this issue and the second one which I've reported (similar security issue with the email - part of credentials). (gain persistence)


SourceNVD

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-fjh6-8679-9pchHIGH8.3
  • JavaScriptJavaScript
  • flowise-ui
NoYesNov 14, 2025
GHSA-x39m-3393-3qp4HIGH8.3
  • JavaScriptJavaScript
  • flowise-ui
NoYesNov 14, 2025
CVE-2025-64756HIGH7.5
  • JavaScriptJavaScript
  • argo-workflows-fips-3.6
NoYesNov 17, 2025
GHSA-m8jr-fxqx-8xx6HIGH7.5
  • JavaScriptJavaScript
  • @apollo/composition
NoYesNov 14, 2025
CVE-2025-64758MEDIUM4.8
  • JavaScriptJavaScript
  • @dependencytrack/frontend
NoYesNov 17, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management