THREAT OPS › Threat News › [GHSA] GHSA-8gj2-2cvc-6xx7 (medium) — Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
[GHSA] GHSA-8gj2-2cvc-6xx7 (medium) — Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
GHSA-8gj2-2cvc-6xx7 Severity: medium CVE: None
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
## Summary
The `/api/v1/text-to-speech/generate` endpoint is whitelisted (requires no authentication) and accepts any `chatflowId` without checking whether the referenced chatflow is public. An unauthenticated attacker w
MITRE ATT&CK techniques
- CredentialsT1589.001
Original source: https://github.com/advisories/GHSA-8gj2-2cvc-6xx7