CVE-2026-90535 | FlowiseAI Flowise up to 3.1.3 Text To Speech Abort abort chatflowId/chatId denial of service

SecurityVulns

A vulnerability categorized as problematic has been discovered in FlowiseAI Flowise up to 3.1.3. Affected is an unknown function of the file /api/v1/text-to-speech/abort of the component Text To Speech Abort. Executing a manipulation of the argument chatflowId/chatId can lead to denial of service.

This vulnerability appears as CVE-2026-90535. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More