CVE-2026-70476

HIGH CVSS 4.0: 8.3 EPSS 0.29%
Updated Aug 05, 2026
Flowise
Parameter Value
CVSS 8.3 (HIGH)
Fixed In 3.1.3
Type CWE-639 (Authorization Bypass), CWE-284 (Improper Access Control)
Vendor Flowise
Public PoC No

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption.

This issue is fixed in 3.1.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products

flowiseai:flowise