Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-91931
9CRITICAL
What is CVE-2026-91931?
Flowise prior to version 3.1.4 is susceptible to a remote code execution vulnerability in the Custom MCP node. This flaw allows authenticated attackers to execute arbitrary code on the Flowise server by manipulating the mcpServerConfig parameter with specially crafted npx package names. By leveraging their access, attackers can invoke npx to run harmful npm packages, potentially compromising the integrity of the server and its data.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 0 < 3.1.4
Flowise 3.1.4
