CVE-2026-73603
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Summary
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FlowiseAI | Flowise | 0 < 3.1.4 | affected |
| FlowiseAI | Flowise | 3.1.4 | unaffected |
Weaknesses
- CWE-862: Missing Authorization
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8gj2-2cvc-6xx7
- https://www.vulncheck.com/advisories/flowise-before-credential-abuse-via-text-to-speech
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.