8.2highHigh

CVE-2026-70476

Flowiseai Flowise

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
8.2 (v3.1)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CVSS v4
8.3
Weakness
CWE-284
Assigned by
security-advisories@github.com

Dates

Published
2026-08-04
Last modified
2026-09-11
Sources
NVD

Affected products

  • Flowiseai Flowise- 3.1.3

As listed in the NVD configuration data. Not a statement about your estate.

References