Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-91931: Flowise before 3.1.4 lets logged‑in users run any code
CVE-2026-91931 · published 25 days ago
Summary
Versions of Flowise older than 3.1.4 allow someone who already has a valid login to run any program on the server. This could let an attacker take control of the system or damage data. Upgrade Flowise to version 3.1.4 or later and monitor logged‑in accounts for unusual activity.
What to do
- Update flowiseai flowise to version 3.1.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| flowiseai | flowise | < 3.1.4 |
Original advisory text
Flowise before 3.1.4 Remote Code Execution via Custom MCP npx
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91931... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91931 Vendor Advisory
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-...
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vcwp-f9rq-3887
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.0
Critical
Type
CWE-78OS Command Injection
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta