THREAT OPS › Threat News › [NVD] CVE-2026-70476 (HIGH 8.2) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts
[NVD] CVE-2026-70476 (HIGH 8.2) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts
CVE-2026-70476 CVSS: 8.2 HIGH Published: 2026-08-04T20:16:54.330
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId valu
Indicators of compromise
- CVE-2026-70476cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70476