HIGH
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
Published Apr 23, 2026
8.2
HIGHCVSS 4.0
EPSS 0.40%
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (no auth) and accepts a credentialId directly in the request body. When called without a chatflowId, the endpoint uses the provided credentialId to decrypt the stored credential (e.g., OpenAI or ElevenLabs API key) and generate speech. This vulnerability is fixed in 3.1.0.
Affected products
-
- Version < 3.1.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
flowise
npm
Introduced 0 Fixed 3.1.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | flowise | 0 | 3.1.0 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25298 Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5fw2-mwhh-9947 x_refsource_CONFIRMExploitVendor Advisory
- https://github.com/advisories/GHSA-5fw2-mwhh-9947 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41279
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25298 | Advisory | |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5fw2-mwhh-9947 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://github.com/advisories/GHSA-5fw2-mwhh-9947 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41279 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 23, 2026
Reserved Apr 18, 2026
Link CVE-2026-41279
CISA Vulnrichment
Updated Apr 23, 2026
ENISA EUVD
EUVD-2026-25298 GHSA-5FW2-MWHH-9947 Assigner GitHub_M
Published Apr 23, 2026
Updated Apr 23, 2026
Exploited since n/a
Link EUVD-2026-25298