CVE-2026-90535

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-12 13:16

Updated : 2026-09-15 19:07


NVD link : CVE-2026-90535

Mitre link : CVE-2026-90535

CVE.ORG link : CVE-2026-90535


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-862

Missing Authorization