{"id":"CVE-2026-56277","aliases":["GHSA-m837-xvxr-vqwg"],"url":"https://o3.security/vulnerability/CVE-2026-56277","summary":"Flowise - Hardcoded CORS Wildcard in TTS Endpoint","details":"Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise restrictive default CORS configuration (getCorsOptions()) and allows any webpage to make cross-origin requests that trigger TTS generation using stored credentials, enabling drive-by cross-origin credential abuse.","published":"2026-06-30T22:08:27.269Z","modified":"2026-08-12T03:51:25.343750173Z","cvss":null,"epss":{"score":0.00136,"percentile":0.03521,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"flowise","fixedVersion":"3.1.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56277.json"},{"type":"ADVISORY","url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-m837-xvxr-vqwg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56277"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/flowise-hardcoded-cors-wildcard-in-tts-endpoint"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.343750173Z"}}