GHSA-8gj2-2cvc-6xx7: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
mediumvulnerability
security
Source: GitHub Advisory DatabaseAugust 4, 2026
Summary
Flowise has a security flaw where the text-to-speech API endpoint doesn't require login and doesn't check if a chatflow is public before allowing access to it. An attacker who knows a chatflow's ID can trick the system into using that chatflow's stored API credentials (like OpenAI or ElevenLabs keys) to generate unlimited audio without permission, costing the real owner money.
Classification
Attack SophisticationTrivial
Impact (CIA+S)
confidentialityintegrityavailability
Affected Vendors
OpenAI
Affected Packages
flowise@<= 3.1.3 (fixed: 3.1.4)
Related Issues
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-8gj2-2cvc-6xx7
First tracked: August 4, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%