Command Execution Vulnerability in Flowise Drag & Drop Interface by FlowiseAI
CVE-2026-69263

8.7HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-69263?

Flowise, a user-friendly interface for building customized language model flows, contains a vulnerability that allows for command execution through the manipulation of npm configuration variables. Before version 3.1.3, the software's mitigation techniques for a previous security issue inadvertently enabled the reproduction of the --yes flag behavior. This allows for unauthorized package installations and executions when launching a Custom MCP server, thereby compromising system security. Users are strongly advised to upgrade to version 3.1.3 to mitigate this risk.

Affected Version(s)

Flowise < 3.1.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.