Skip to content
Remote Code Execution Vulnerabilities in Flowise and Spug Applications

Remote Code Execution Vulnerabilities in Flowise and Spug Applications

First seen 15 Sep 2026, 21:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 22:59 UTC
  • Flowise and Spug applications have critical remote code execution vulnerabilities.
  • Affected versions are Flowise before 3.1.4 and Spug through 3.4.0.
  • CWE-78 indicates improper neutralization of OS commands, enabling potential exploits.

Two separate remote code execution vulnerabilities have been identified in Flowise and Spug applications. Flowise versions before 3.1.4 and Spug versions through 3.4.0 are affected by CWE-78, which allows OS command injection. Attackers can exploit these vulnerabilities to execute arbitrary commands on the host system. The vulnerabilities were disclosed in advisories published on September 15 and September 13, 2026, respectively. No specific CVEs were mentioned in the articles. Organizations using these applications are advised to prioritize patching. The scope of impact includes any systems running the affected versions of Flowise and Spug. Current status indicates that these vulnerabilities are known but exploitation details remain unclear.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-13
Spug vulnerability disclosed
Advisory published detailing remote code execution via ping_check in Spug versions through 3.4.0.
Vulncheck
2026-09-15
Flowise vulnerability disclosed
Advisory published detailing remote code execution via custom Mcp Npx in Flowise versions before 3.1.4.
Vulncheck

More articles in this cluster (4)