If you're logged into your e-mail, then someone can go to Facebook, and start password recovery, and then go to your e-mail and click the recovery link. If you're not logged in, then the OpenID authentication will require you to enter your e-mail. This isn't a weakness, just a convenience.
How is that not a weakness if anyone who has access to your computer can set an arbitrary password on your facebook account? (given you are logged into your gmail). I think it would be a nice feature if facebook would use that information to force a relogin