Skip to content

MCPA-2026-0055

mediumauth-missing

Flowise unauthenticated text-to-speech endpoint abuses private chatflow TTS credentials (GHSA-8gj2-2cvc-6xx7)

Flowise 3.1.3 and earlier expose a text-to-speech endpoint without authorization checks, letting unauthenticated callers consume the TTS credentials configured on private chatflows. Fixed in 3.1.4 (note: one release later than the 3.1.3 batch).

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.4

Identifiers

GHSA-8gj2-2cvc-6xx7CWE-862

References

Timeline

  • Published: 2026-08-04

← All advisories