Executive brief
Flowise, an open-source tool for building LLM applications, contains a security flaw in its Text-to-Speech (TTS) component. A technical misconfiguration allows any website on the internet to interact with the TTS service using a victim's saved credentials. This could lead to unauthorized use of paid speech generation services or the exposure of sensitive configuration data if a user visits a malicious webpage while logged into Flowise.
Technical details
The Text-to-Speech (TTS) generation endpoint in Flowise incorrectly implements Cross-Origin Resource Sharing (CORS) by hardcoding the 'Access-Control-Allow-Origin' header to a wildcard ('*'). This configuration bypasses the server's global restrictive CORS policy defined in 'getCorsOptions()'. Because this header is set independently of the standard middleware, it allows any third-party domain to make authenticated requests to the TTS endpoint if a user has an active session. An attacker can exploit this to trigger speech generation or abuse stored TTS credentials via a drive-by attack from a malicious website. The issue is fixed in version 3.1.2 by removing the hardcoded headers and allowing the standard CORS middleware to manage access.
Affected products
- FlowiseAI flowise <= 3.1.1
Timeline
- 2026-05-14: disclosed
- 2026-05-20: advisory: GitHub Advisory published
- 2026-05-20: patched: Version 3.1.2 released