CVE-2026-91932
Flowise before 3.1.4 Remote Code Execution via cwd Parameter
Description
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
In plain language
AI Worth attentionFlowise versions before 3.1.4 let a logged-in attacker run harmful code, so businesses using those versions should schedule an upgrade.
Authenticated RCE in Flowise before 3.1.4 via a validation bypass in MCP server configuration that allows control of the cwd parameter.
What to do now
- Check the installed Flowise version and whether users can change MCP server configurations.
- Upgrade Flowise to version 3.1.4 or later.
- Until upgraded, limit MCP configuration access to trusted administrators and review recent configuration changes.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-91932 and every CVE in our database. Create a free account — no credit card required.
Create Free Account