Description
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Flowise before 3.1.4 contains a vulnerability in the Custom MCP node that allows an attacker who is authenticated to the Flowise system to execute arbitrary code on the server. By supplying specially crafted npx package names in the mcpServerConfig parameter, the attacker can trigger npx to download and run attacker‑controlled npm packages, resulting in full code execution on the Flowise host.

Affected Systems

The affected product is Flowise by FlowiseAI, with all releases prior to version 3.1.4 vulnerable. Any deployment of Flowise that includes the Custom MCP node and has users with authentication privileges can be impacted.

Risk and Exploitability

The CVSS score of 9 indicates a critical severity level. The EPSS score is < 1%, but the lack of a KEV listing suggests no widely known exploitation at this time. However, because the flaw requires authentication, it is likely to be targeted by internal attackers or compromised credentials. If successfully exploited, an attacker can execute arbitrary code, giving full control over the Flowise server and any connected resources.

Generated by OpenCVE AI on September 20, 2026 at 16:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 or later to remove the vulnerability.
  • If an upgrade is not possible, disable the Custom MCP node in all non‑admin deployments or configure it so that the mcpServerConfig parameter cannot accept arbitrary npx package names.
  • Restrict execution of npx or block external npm package downloads by applying network or container escape controls, ensuring that only trusted packages can be installed.

Generated by OpenCVE AI on September 20, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
Title Flowise before 3.1.4 Remote Code Execution via Custom MCP npx
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-78
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:49:53.465Z

Reserved: 2026-09-15T11:06:02.263Z

Link: CVE-2026-91931

cve-icon Vulnrichment

Updated: 2026-09-17T14:49:44.875Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:43.883

Modified: 2026-09-23T17:17:47.090

Link: CVE-2026-91931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')