PT-2026-71429 · Flowise · Flowise

·

CVE-2026-73601

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.3
Description Authenticated users can achieve remote code execution in the Custom MCP node when the CUSTOM MCP PROTOCOL is set to stdio. This occurs through the manipulation of command arguments and environment variables. Specifically, attackers can exploit the PYTHONWARNINGS and BROWSER environment variables when using python3, or utilize the root working directory with node to bypass validation and execute arbitrary system commands.
Recommendations Update Flowise to version 3.1.3 or later.

Exploit

Fix

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73601
GHSA-G98Q-RM45-Q9H8

Affected Products

Flowise