๐Ÿ” CVE Alert

CVE-2026-73603

UNKNOWN 0.0

Flowise before 3.1.4 Credential Abuse via Text-to-Speech

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.

CWE CWE-862
Vendor flowiseai
Product flowise
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for flowiseai flowise

Be the first to know when new unknown vulnerabilities affecting flowiseai flowise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FlowiseAI / Flowise
0 < 3.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8gj2-2cvc-6xx7 vulncheck.com: https://www.vulncheck.com/advisories/flowise-before-credential-abuse-via-text-to-speech

Credits

๐Ÿ” offset