CyberRota Analysis
AI-GeneratedFlowise versions prior to 3.1.4 are vulnerable due to inadequate validation of chatflow visibility in the unauthenticated text-to-speech endpoint, enabling attackers to misuse private chatflow TTS credentials. This flaw allows unauthorized users to generate unlimited text-to-speech audio using the owner's OpenAI or ElevenLabs API keys, potentially leading to significant financial costs for the affected account. Organizations utilizing Flowise should prioritize patching to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.