Description
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Flowise versions prior to 3.1.4 contain a flaw that bypasses input validation in the MCP server configuration. An authenticated attacker can manipulate the unvalidated cwd parameter while supplying a clean filename in the args array, allowing the server to change its working directory and execute arbitrary code with the privileges of the Flowise service. This vulnerability is a classic example of CWE‑20, Improper Input Validation, and results in remote code execution, which can lead to complete host compromise, data loss, or network infiltration.

Affected Systems

All releases of Flowise by FlowiseAI up to, but not including, version 3.1.4 are affected. Users who run any of these versions, regardless of deployment environment, should verify their installed version and update if necessary.

Risk and Exploitability

The CVSS score of 9 indicates a severe potential impact. However, the EPSS score of less than 1% suggests a very low probability of exploitation under current conditions. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need authenticated access to submit a crafted request that sets a clean filename in args and controls the cwd parameter, thereby hijacking the working directory to run malicious code.

Generated by OpenCVE AI on September 20, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Flowise version 3.1.4 or later to fix the validation bypass that permits remote code execution.
  • If a patch is not immediately available, block inbound requests to the MCP server configuration endpoint or enforce strict authentication controls to prevent attackers from submitting malicious cwd parameters.
  • Implement network segmentation and least‑privilege policies around the Flowise deployment to limit the scope of potential code execution if an attacker gains access.

Generated by OpenCVE AI on September 20, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
Title Flowise before 3.1.4 Remote Code Execution via cwd Parameter
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-20
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:07:11.412Z

Reserved: 2026-09-15T11:06:02.263Z

Link: CVE-2026-91932

cve-icon Vulnrichment

Updated: 2026-09-15T16:07:05.842Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:44.030

Modified: 2026-09-16T20:17:00.597

Link: CVE-2026-91932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses
  • CWE-20

    Improper Input Validation