CVE-2026-91936
Flowise before 3.1.4 Script Injection via Docker Workflows
Description
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
In plain language
AI Low urgencyFlowise versions before 3.1.4 have a flaw that lets someone already allowed to change its project files run unwanted commands, so most small businesses should schedule an update rather than treat this as an emergency.
CWE-78 command injection in Flowise Docker build workflows allows repository write-access users to inject shell commands through workflow-dispatch inputs interpolated into run blocks.
What to do now
- Check whether you use Flowise and whether its version is earlier than 3.1.4.
- Upgrade Flowise to version 3.1.4 or later.
- Review who can edit the Flowise project and remove unnecessary write access.
- If untrusted people had write access, replace cloud and container-service access keys used by builds.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:NConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-91936 and every CVE in our database. Create a free account — no credit card required.
Create Free Account