Unauthorized Stripe Operations in Flowise by FlowiseAI
CVE-2026-70476
8.3HIGH
What is CVE-2026-70476?
Flowise, a drag & drop interface for building customizable large language model flows, contains a vulnerability in its organizational billing endpoints. In versions before 3.1.3, these endpoints do not properly verify the ownership of the Stripe subscriptionId. This oversight allows authenticated attackers to manipulate subscriptions of other users' organizations, potentially leading to unauthorized plan changes and modifications to seat quantities. As a result, organizations can face significant financial repercussions and service disruptions. The issue has been addressed in version 3.1.3.
Affected Version(s)
Flowise < 3.1.2
