Flowise Custom MCP env var denylist bypass enables RCE (CVE-2026-58057)
Flowise before 3.1.3 compared Custom MCP stdio environment variable names against a denylist case-sensitively, so on Windows an authenticated user could supply 'node_options' to bypass the NODE_OPTIONS block. This allowed injection of NODE_OPTIONS --require and arbitrary code execution in the Flowise server context.
Disclosed 28 June 2026 · Record updated 13 September 2026
Impact
An authenticated user able to configure a Custom MCP node could execute arbitrary code in the Flowise server context on Windows hosts; fixed in version 3.1.3.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-58057
