Vulnerability  ·  2026-06-24

Flowise Custom MCP Server OS Command Injection via Incomplete Flag Validation and Regex Bypass

VulnerabilityHigh impactGlobalCVE-2026-56274
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature. Incomplete command-flag validation and a bypass of the local file access restriction regex allow any authenticated Flowise user (any role) or an API user with view/update permissions to inject arbitrary OS commands that are executed by the server. CVSS 9.9 Critical, published 2026-06-23.
Flowise is a widely-used no-code LLM agent builder. The MCP integration is a primary use case. This means any low-privilege Flowise account holder — including API integrations — can achieve full server RCE through the MCP feature, compromising the underlying host, all stored credentials, connected data sources, and agent tool access.
Authenticated HTTP request to the Custom MCP Server configuration endpoint with crafted command flags or regex-bypassing payloads; OS commands execute as the Flowise server process
Flowise < 3.1.2
Upgrade to Flowise 3.1.2. Advisory: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-m99r-2hxc-cp3q
Sources
NVD CVE-2026-56274GitHub Advisory GHSA-m99r-2hxc-cp3qMallory AI CVE-2026-56274
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →