Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-15 17:17
NVD link : CVE-2026-91932
Mitre link : CVE-2026-91932
CVE.ORG link : CVE-2026-91932
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
