Script Injection Vulnerability in Flowise Docker Image Builds
CVE-2026-91936
8.3HIGH
What is CVE-2026-91936?
Flowise versions prior to 3.1.4 are vulnerable to a script injection flaw within Docker image build workflows. This issue arises when workflow_dispatch inputs are interpolated directly into shell run blocks, enabling attackers with repository write access to inject shell metacharacters. As a result, malicious actors can execute arbitrary commands, potentially leading to the compromise of sensitive information such as AWS credentials and Docker Hub tokens.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 3.1.4
