Skip to content
Critical Remote Code Execution Flaw Discovered in Flowise MCP Server

Critical Remote Code Execution Flaw Discovered in Flowise MCP Server

First seen 23 Jun 2026, 23:47 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 24, 2026 at 22:55 UTC
  • CVE-2026-56274 is a critical remote code execution vulnerability in Flowise before version 3.1.2.
  • Attackers can exploit multiple OS command injection paths with any Flowise account role.
  • Organizations are urged to upgrade to version 3.1.2 and review their MCP server configurations.

Flowise has disclosed a critical remote code execution vulnerability, tracked as CVE-2026-56274, affecting versions prior to 3.1.2 of its Custom MCP Server feature. The flaw allows attackers to exploit multiple OS command injection paths in the validateCommandFlags and validateArgsForLocalFileAccess functions. Attackers with any Flowise account role or API access can configure a malicious MCP server, leading to arbitrary command execution on the Flowise host. The vulnerability has a CVSS score of 9.9, indicating high severity and remote exploitability. Organizations are advised to upgrade to Flowise version 3.1.2 or later and review their MCP server configurations. Three bypass techniques have been identified, including an incomplete Docker argument blocklist and a regex bypass in local file access checks. The vulnerability was published on June 23, 2026, and poses a significant risk to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-23
CVE-2026-56274 published
Flowise disclosed a critical remote code execution vulnerability affecting versions before 3.1.2 due to MCP security bypasses.
Mallory.Ai
2026-06-23
CVE-2026-56274 details released
Cvefeed.io reported on multiple OS command injection vulnerabilities in Flowise's Custom MCP Server feature.
cvefeed.io

More articles in this cluster (4)

Following this threat?

Track CVE-2026-56274 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed