Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.0

CVE-2026-91932: Flowise lets attackers run code on server

CVE-2026-91932 · published 24 days ago
Summary

Versions of Flowise earlier than 3.1.4 let a user who has logged in manipulate a setting called the cwd parameter to run their own code on the server. This could let an attacker take control of the system that runs Flowise. Upgrade Flowise to version 3.1.4 or later to close the risk.

What to do
  • Update flowiseai flowise to version 3.1.4 or later.
Affected software
VendorProductAffected versions
flowiseai flowise < 3.1.4
Original advisory text
Flowise before 3.1.4 Remote Code Execution via cwd Parameter
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.0 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-91932 · MITRE
Track software like this
Free during beta