Impact
Flowise versions prior to 3.1.3 allow authenticated users to supply arbitrary Stripe subscriptionId values when calling organization‑billing endpoints without checking that the subscription belongs to their tenant. The flaw permits an attacker to change subscription plans, alter seat quantities, or otherwise perform Stripe operations on other tenants, causing direct financial damage and potential service disruption.
Affected Systems
The affected product is FlowiseAI Flowise. All releases before 3.1.3 are vulnerable; 3.1.3 and later include the fix.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is uncertain. An attacker must be an authenticated user in the system; from that race condition, they can manipulate other tenants’ billing by sending crafted requests to the existing endpoints.
OpenCVE Enrichment
Github GHSA