Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-91931

9CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91931?

Flowise prior to version 3.1.4 is susceptible to a remote code execution vulnerability in the Custom MCP node. This flaw allows authenticated attackers to execute arbitrary code on the Flowise server by manipulating the mcpServerConfig parameter with specially crafted npx package names. By leveraging their access, attackers can invoke npx to run harmful npm packages, potentially compromising the integrity of the server and its data.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DavidCarliez
.