CVE 8.7 HIGH

Flowise – Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess_CVE-2026-56274

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for example, 'docker build' is not blocked, and 'npx --yes' is not blocked while only '-y' is) and the validateArgsForLocalFileAccess checks, resulting in execution of arbitrary commands on the Flowise host.

AI Analysis

Remote code execution vulnerability via MCP security bypass in validateCommandFlags and validateArgsForLocalFileAccess

Basic Information

ID CVE-2026-56274
Source VulnCheck
Published Jun 23, 2026 at 12:13

Affected Product

Vendor Flowise
Product Flowise
Affected Versions Flowise Flowise 0
Flowise Flowise 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Flowise
Product Flowise
Version before 3.1.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.