CVE-2026-91932
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.82%
- CWE
- CWE-20
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- FlowiseAI Flowise
- FlowiseAI Flowise
Weakness type
Related vulnerabilities
- CVE-2026-78900 — Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
- CVE-2026-79111 — Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execu
- CVE-2026-84325 — Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging s
- CVE-2026-79230 — Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potent
- CVE-2026-79182 — Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
- CVE-2026-78963 — Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
- CVE-2026-79008 — Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had
- CVE-2026-87553 — Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had com