Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-73603

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 26.5%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2026-73603


Contact Us

Shodan ® - All rights reserved