Improper access control in Flowise - #VU131711
Published: May 18, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to abuse stored credentials to generate speech cross-origin.
The vulnerability exists due to improper access control in the TTS generation endpoint when handling cross-origin requests. A remote attacker can send a request from any webpage to abuse stored credentials to generate speech cross-origin.
The issue bypasses the server's otherwise restrictive default CORS policy.