Skip to content

Security: zwayth/openspeech

Security

docs/SECURITY.md

Security

Reporting a vulnerability

Please report security issues privately through GitHub's private vulnerability reporting rather than in a public issue. We aim to acknowledge a report within a few days.

Scope and threat model

OpenSpeech is a local library and an internal service. A few properties are worth being explicit about.

The HTTP service has no authentication or authorisation. It is designed to run behind something that does. Do not expose it directly to the internet.

Uploaded audio is written to disk. Job inputs and outputs go to a temporary directory by default. Set storage on create_app() to control where, and clean it on a schedule appropriate to your data. Input files are deleted after a job runs; outputs are kept so they can be fetched.

Requests reach an LLM only when you ask. The rule planner is entirely local. --llm and use_llm send the request text — not the audio — to whatever endpoint LLM_BASE_URL names. Treat request text as you would any other user data.

Generated audio is a synthesis of a voice. AuK can clone a voice from a reference recording. Whether you have the right to do that with a given recording is a question this software cannot answer for you. Applicable law varies by jurisdiction and is changing; consent from the speaker is the baseline.

Recipes and plans are data, not code. Studio recipes are parsed as JSON or with yaml.safe_load. Neither can execute code. Operation names and parameters from a recipe, an LLM, or an HTTP request are all validated through the same registry before anything runs, so an unknown operation or an out-of-range value is rejected rather than forwarded.

Model weights are not verified. OpenSpeech loads whatever checkpoint you point it at, through AuK. Obtain weights from the official Hugging Face or ModelScope releases.

Supported versions

This project is pre-1.0. Security fixes land on main and in the next release.

There aren't any published security advisories