MCPA-2026-0055
mediumauth-missing
Flowise unauthenticated text-to-speech endpoint abuses private chatflow TTS credentials (GHSA-8gj2-2cvc-6xx7)
Flowise 3.1.3 and earlier expose a text-to-speech endpoint without authorization checks, letting unauthenticated callers consume the TTS credentials configured on private chatflows. Fixed in 3.1.4 (note: one release later than the 3.1.3 batch).
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, < 3.1.4 |
Identifiers
GHSA-8gj2-2cvc-6xx7CWE-862
References
- advisory https://github.com/advisories/GHSA-8gj2-2cvc-6xx7
- advisory https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8gj2-2cvc-6xx7
Timeline
- Published: 2026-08-04