Impact
Flowise versions prior to 3.1.4 contain a flaw that bypasses input validation in the MCP server configuration. An authenticated attacker can manipulate the unvalidated cwd parameter while supplying a clean filename in the args array, allowing the server to change its working directory and execute arbitrary code with the privileges of the Flowise service. This vulnerability is a classic example of CWE‑20, Improper Input Validation, and results in remote code execution, which can lead to complete host compromise, data loss, or network infiltration.
Affected Systems
All releases of Flowise by FlowiseAI up to, but not including, version 3.1.4 are affected. Users who run any of these versions, regardless of deployment environment, should verify their installed version and update if necessary.
Risk and Exploitability
The CVSS score of 9 indicates a severe potential impact. However, the EPSS score of less than 1% suggests a very low probability of exploitation under current conditions. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need authenticated access to submit a crafted request that sets a clean filename in args and controls the cwd parameter, thereby hijacking the working directory to run malicious code.
OpenCVE Enrichment