Unauthenticated Denial of Service in Flowise by FlowiseAI
CVE-2026-90535
6.3MEDIUM
What is CVE-2026-90535?
Flowise versions prior to 3.1.4 are susceptible to an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint. This vulnerability allows attackers to disrupt service by sending requests with specific chatflowId and chatId without verifying ownership, enabling them to terminate active chat flow predictions for any user. Consequently, this can lead to significant disruptions in service, impacting user experience and application reliability.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 3.1.4
