Impact
A flaw in Flowise prior to version 3.1.4 allows an unauthenticated attacker to supply a valid chatflow UUID to the text‑to‑speech endpoint. Because the endpoint ignores visibility checks, the attacker can use any stored OpenAI or ElevenLabs API keys associated with that chatflow, producing unlimited audio output. This represents a CWE‑862 weak authorization flaw and the resulting service consumption can incur significant charges on the account of the chatflow owner and represent a direct financial exploitation vector.
Affected Systems
The vulnerability affects FlowiseAI: Flowise across all versions earlier than 3.1.4. Any instance of Flowise installed before the 3.1.4 release that includes the TTS endpoint is susceptible, regardless of other configurations, provided it is accessible to unauthenticated users and holds private chatflows with third‑party TTS credentials.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. Because the exploit requires only knowledge of a valid chatflow UUID and does not require authentication, the attack surface is large for targeted or discovered UUIDs. EPSS scores are not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the TTS endpoint, and if mitigated, the impact is largely financial through additional API usage.
OpenCVE Enrichment