GHSA-4xpg-6vjv-3v64MediumCVSS 7.5
Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the ...
🔗 CVE IDs covered (1)
📋 Description
Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.