HIGH
CVE-2026-70476
CVSS
8.2
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.
Weakness (CWE)
CWE-284
Improper Access Control
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.32%
Probability of exploitation in next 30 days
24.9th percentile
References
https://github.com/FlowiseAI/Flowise/commit/4d7899d02ca370a5510406be5c91483085a412f9
Patch
https://github.com/FlowiseAI/Flowise/pull/6321
Issue Tracking, Patch
https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3
Release Notes
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p
Exploit, Vendor Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.