HIGH

CVE-2026-90535

Flowiseai Flowise 2026-09-12 CVSS v3.1
CVSS
7.5

Description

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.27%
Probability of exploitation in next 30 days
19.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE