Critical Remote Code Execution Flaw Discovered in Flowise MCP Server

Critical Remote Code Execution Flaw Discovered in Flowise MCP Server

1h ago Mallory.Aicvefeed.iowww.vulncheck.comgithub.com 92% similarity 78.0
Share:

Article Content

Browse articles
ThreatCluster

Flowise has disclosed a critical remote code execution vulnerability, tracked as CVE-2026-56274, affecting versions prior to 3.1.2 of its Custom MCP Server feature. The flaw allows attackers to exploit multiple OS command injection paths in the validateCommandFlags and validateArgsForLocalFileAccess functions. Attackers with any Flowise account role or API access can configure a malicious MCP server, leading to arbitrary command execution on the Flowise host. The vulnerability has a CVSS score of 9.9, indicating high severity and remote exploitability. Organizations are advised to upgrade to Flowise version 3.1.2 or later and review their MCP server configurations. Three bypass techniques have been identified, including an incomplete Docker argument blocklist and a regex bypass in local file access checks. The vulnerability was published on June 23, 2026, and poses a significant risk to affected systems.

Key Points: • CVE-2026-56274 is a critical remote code execution vulnerability in Flowise before version 3.1.2. • Attackers can exploit multiple OS command injection paths with any Flowise account role. • Organizations are urged to upgrade to version 3.1.2 and review their MCP server configurations.

ThreatCluster AI

Timeline

2026-06-23
CVE-2026-56274 published
Flowise disclosed a critical remote code execution vulnerability affecting versions before 3.1.2 due to MCP security bypasses.
Mallory.Ai
2026-06-23
CVE-2026-56274 details released
Cvefeed.io reported on multiple OS command injection vulnerabilities in Flowise's Custom MCP Server feature.
cvefeed.io

Community

Browse all →