Remote Code Execution Vulnerability in Flowise MCP Server Configuration
CVE-2026-91932
9CRITICAL
What is CVE-2026-91932?
Flowise versions before 3.1.4 contain a vulnerability that allows authenticated attackers to execute arbitrary code remotely. This is achieved through a validation bypass in the MCP server configuration, specifically by manipulating the cwd parameter. Attackers can exploit this weakness by using sanitized filenames in the arguments array, effectively bypassing the intended path validation, thus gaining control of the working directory to execute malicious scripts.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 0 < 3.1.4
Flowise 3.1.4
