AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73603

MEDIUM · CVSS 6.3 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Flowise versions prior to 3.1.4 are vulnerable due to inadequate validation of chatflow visibility in the unauthenticated text-to-speech endpoint, enabling attackers to misuse private chatflow TTS credentials. This flaw allows unauthorized users to generate unlimited text-to-speech audio using the owner's OpenAI or ElevenLabs API keys, potentially leading to significant financial costs for the affected account. Organizations utilizing Flowise should prioritize patching to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73603
Severity
MEDIUM
CVSS
6.3
EPSS
0.32%

Original NVD Description

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.