CVE-2026-70476High· 8.2▾ TwilightFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterp…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
8.2 → —
— → 8.2
8.2 → —
— → 8.2
8.2 → —
— → 8.2
8.2 → —
— → 8.2
8.2 → —
— → 8.2
8.2 → —
— → 8.2
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.
flowise < 3.1.3Upgrade past the affected range:
flowise 3.1.3Affected packages:
flowise <= 3.1.2Patched in:
flowise 3.1.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
GHSA-2364-jh4q-m9vmMediumFlowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
CVE-2026-69258Critical· 9.1Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-69250High· 7.5Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-70475Medium· 6.5Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-70477Critical· 9.8Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-70471Medium· 6.5Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows