Remote Code Execution in Flowise by FlowiseAI
CVE-2026-73601
9CRITICAL
What is CVE-2026-73601?
Flowise versions prior to 3.1.3 are compromised by a remote code execution vulnerability within the Custom MCP node. When the CUSTOM_MCP_PROTOCOL is configured to stdio, authenticated users may exploit this flaw to execute arbitrary commands by manipulating environment variables and command-line arguments. Attackers can misuse the PYTHONWARNINGS and BROWSER environment variables in the context of python3, or leverage the root working directory using node, thereby bypassing essential validations to run system commands. This vulnerability poses a significant risk to the integrity of server operations, necessitating immediate attention and remediation.
Affected Version(s)
Flowise 0 < 3.1.3
Flowise 0 < 3.1.3
Flowise 3.1.3
