PT-2026-71431 · Flowise · Flowise
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.4
Description
An issue exists where the software fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint. This allows unauthenticated attackers to abuse private chatflow text-to-speech credentials by providing a valid
chatflow UUID. Consequently, attackers can generate unlimited audio using stored OpenAI or ElevenLabs API keys, leading to financial costs for the chatflow owner.Recommendations
Update to version 3.1.4 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise