Description
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.
Published: 2026-08-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Flowise prior to version 3.1.4 allows an unauthenticated attacker to supply a valid chatflow UUID to the text‑to‑speech endpoint. Because the endpoint ignores visibility checks, the attacker can use any stored OpenAI or ElevenLabs API keys associated with that chatflow, producing unlimited audio output. This represents a CWE‑862 weak authorization flaw and the resulting service consumption can incur significant charges on the account of the chatflow owner and represent a direct financial exploitation vector.

Affected Systems

The vulnerability affects FlowiseAI: Flowise across all versions earlier than 3.1.4. Any instance of Flowise installed before the 3.1.4 release that includes the TTS endpoint is susceptible, regardless of other configurations, provided it is accessible to unauthenticated users and holds private chatflows with third‑party TTS credentials.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. Because the exploit requires only knowledge of a valid chatflow UUID and does not require authentication, the attack surface is large for targeted or discovered UUIDs. EPSS scores are not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the TTS endpoint, and if mitigated, the impact is largely financial through additional API usage.

Generated by OpenCVE AI on August 13, 2026 at 13:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 or later to apply the vendor patch.
  • If upgrading is delayed, restrict the text‑to‑speech endpoint to authenticated users only or remove public access to that route.
  • Revoke or rotate any OpenAI or ElevenLabs API keys that are associated with private chatflows and monitor for unusual usage patterns.

Generated by OpenCVE AI on August 13, 2026 at 13:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.
Title Flowise before 3.1.4 Credential Abuse via Text-to-Speech
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-862
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-14T22:27:58.527Z

Reserved: 2026-08-13T11:15:12.096Z

Link: CVE-2026-73603

cve-icon Vulnrichment

Updated: 2026-08-14T22:27:53.830Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T12:17:24.617

Modified: 2026-08-31T20:25:28.573

Link: CVE-2026-73603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:15:04Z

Weaknesses