THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8gj2-2cvc-6xx7 (medium) — Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

[GHSA] GHSA-8gj2-2cvc-6xx7 (medium) — Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

medgithub_advisoriesPublished 2026-08-04

GHSA-8gj2-2cvc-6xx7 Severity: medium CVE: None

Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

## Summary

The `/api/v1/text-to-speech/generate` endpoint is whitelisted (requires no authentication) and accepts any `chatflowId` without checking whether the referenced chatflow is public. An unauthenticated attacker w

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-8gj2-2cvc-6xx7