Description
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Flowise versions before 3.1.4 are vulnerable to a command injection flaw in Docker image build workflows. The flaw arises when workflow_dispatch inputs are interpolated directly into shell run blocks, allowing attackers who can write to the repository to inject shell metacharacters via fields such as tag_version and node_version. This injection permits arbitrary command execution, potentially leading to credential theft or other malicious activity.

Affected Systems

The vulnerability affects FlowiseAI’s Flowise product when deployed with Docker workflows and using any version earlier than 3.1.4. Users of the Flowise application who manage workflow_dispatch parameters in their GitHub Actions or similar automation are directly impacted.

Risk and Exploitability

With a CVSS score of 8.3, the flaw presents a serious risk, and although the EPSS score is less than 1%, the lack of a listing in CISA KEV suggests limited publicly known exploits yet the high severity warrants proactive mitigation. Attackers need repository write access to trigger the vulnerable workflow, a condition that can be satisfied by authenticated collaborators or breached credentials. Once the payload runs, the attacker can execute arbitrary commands, potentially exfiltrating AWS credentials and Docker Hub tokens. The attack vector is inferred to be through GitHub Actions or similar CI/CD pipelines that use Docker image build steps where the unchecked inputs are incorporated.

Generated by OpenCVE AI on September 20, 2026 at 16:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 or later.
  • Limit repository write permissions to trusted users only.
  • Sanitize or validate the workflow_dispatch inputs to prevent shell metacharacter injection.
  • Implement monitoring for unexpected command execution or unusual credential usage.

Generated by OpenCVE AI on September 20, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
Title Flowise before 3.1.4 Script Injection via Docker Workflows
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-78
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:50:54.451Z

Reserved: 2026-09-15T11:06:02.263Z

Link: CVE-2026-91936

cve-icon Vulnrichment

Updated: 2026-09-17T14:50:48.885Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:45.013

Modified: 2026-09-17T15:16:57.303

Link: CVE-2026-91936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')