THREAT OPS › Threat News › [NVD] CVE-2026-73603 (MEDIUM 5.3) — Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API key
[NVD] CVE-2026-73603 (MEDIUM 5.3) — Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API key
CVE-2026-73603 CVSS: 5.3 MEDIUM Published: 2026-08-13T12:17:24.617
Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring cost
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-73603cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73603