GitHub Security Advisory (GHSA-8gj2-2cvc-6xx7)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8gj2-2cvc-6xx7 CVE-2026-73603
MEDIUM
Flowise before 3.1.4 Credential Abuse via Text-to-Speech
Record summary
CVE-2026-73603 has a selected CVSS score of 6.3 (medium).
Description
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.4 | affected |
| 3.1.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73603 VulnCheck Advisory: Flowise before 3.1.4 Credential Abuse via Text-to-SpeechThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-credential-abuse-via-text-to-speech