Missing Authorization in Flowise - CVE-2026-90535
Published: August 31, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing authorization in the /api/v1/text-to-speech/abort endpoint when handling crafted abort requests with user-supplied chatflowId and chatId values. A remote attacker can send a specially crafted request to cause a denial of service.
The issue can terminate an in-progress chatflow prediction for another user and may also disrupt client-side UI state through server-sent events.