Junglewise Threat Intelligence

Flowise permissive CORS policy in Text-to-Speech endpoint

Severity: medium · CVSS 6.9 · Published 2026-05-20

Technologies: FlowiseAI Flowise, flowise (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise, an open-source tool for building LLM applications, contains a security flaw in its Text-to-Speech (TTS) component. A technical misconfiguration allows any website on the internet to interact with the TTS service using a victim's saved credentials. This could lead to unauthorized use of paid speech generation services or the exposure of sensitive configuration data if a user visits a malicious webpage while logged into Flowise.

Technical details

The Text-to-Speech (TTS) generation endpoint in Flowise incorrectly implements Cross-Origin Resource Sharing (CORS) by hardcoding the 'Access-Control-Allow-Origin' header to a wildcard ('*'). This configuration bypasses the server's global restrictive CORS policy defined in 'getCorsOptions()'. Because this header is set independently of the standard middleware, it allows any third-party domain to make authenticated requests to the TTS endpoint if a user has an active session. An attacker can exploit this to trigger speech generation or abuse stored TTS credentials via a drive-by attack from a malicious website. The issue is fixed in version 3.1.2 by removing the hardcoded headers and allowing the standard CORS middleware to manage access.

Affected products

  • FlowiseAI flowise <= 3.1.1

Timeline

  • 2026-05-14: disclosed
  • 2026-05-20: advisory: GitHub Advisory published
  • 2026-05-20: patched: Version 3.1.2 released

References

Related threats