Command Execution Vulnerability in Flowise Drag & Drop Interface by FlowiseAI
CVE-2026-69263
8.7HIGH
What is CVE-2026-69263?
Flowise, a user-friendly interface for building customized language model flows, contains a vulnerability that allows for command execution through the manipulation of npm configuration variables. Before version 3.1.3, the software's mitigation techniques for a previous security issue inadvertently enabled the reproduction of the --yes flag behavior. This allows for unauthorized package installations and executions when launching a Custom MCP server, thereby compromising system security. Users are strongly advised to upgrade to version 3.1.3 to mitigate this risk.
Affected Version(s)
Flowise < 3.1.3
