CVE-2026-73603: Flowise before 3.1.4 Credential Abuse via Text-to-Speech
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73603?
The severity of CVE-2026-73603 is rated at 62, indicating a moderate risk associated with the vulnerability.
How do I fix CVE-2026-73603?
To fix CVE-2026-73603, upgrade to Flowise version 3.1.4 or later.
What type of attack does CVE-2026-73603 facilitate?
CVE-2026-73603 facilitates credential abuse by allowing unauthorized access to private chatflow text-to-speech functionalities.
Which versions of Flowise are affected by CVE-2026-73603?
Versions of Flowise prior to 3.1.4 are affected by CVE-2026-73603.
What can attackers do using CVE-2026-73603?
Attackers can generate unlimited text-to-speech audio by exploiting the unauthenticated text-to-speech endpoint with private API keys.