Executive brief
Flowise, an open-source tool for building LLM applications, contains a security flaw in its text-to-speech (TTS) feature. The system incorrectly allows any website on the internet to interact with this specific feature, bypassing standard security boundaries. This could allow a malicious website to trick a user's browser into using the user's saved credentials to generate speech, potentially leading to unauthorized use of paid services or credential abuse.
Technical details
Flowise versions prior to 3.1.2 contain an origin validation error (CWE-346) in the text-to-speech (TTS) generation endpoint located at `packages/server/src/controllers/text-to-speech/index.ts`. The endpoint explicitly sets the `Access-Control-Allow-Origin` header to a wildcard (`*`), which overrides the server's global restrictive CORS policy. This configuration allows any third-party domain to initiate cross-origin requests to the TTS service. When combined with stored credentials, an attacker can perform drive-by credential abuse via a malicious webpage to trigger TTS generation. The issue is resolved in version 3.1.2 by removing the hardcoded headers and deferring to the standard middleware.
Affected products
- FlowiseAI Flowise < 3.1.2
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date