CVE-2026-56277
EUVD-2026-4043230.06.2026, 23:17
Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise restrictive default CORS configuration (getCorsOptions()) and allows any webpage to make cross-origin requests that trigger TTS generation using stored credentials, enabling drive-by cross-origin credential abuse.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flowiseai | flowise | 𝑥 < 3.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration