THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70476 (HIGH 8.2) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts

[NVD] CVE-2026-70476 (HIGH 8.2) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts

lownvdPublished 2026-08-04

CVE-2026-70476 CVSS: 8.2 HIGH Published: 2026-08-04T20:16:54.330

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId valu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70476