Multiple remote code execution flaws in Flowise AI agent-builder platform
Three CVEs disclosed against FlowiseAI's Flowise low-code LLM/agent workflow platform allow remote code execution on the host, including unauthenticated RCE via the Custom MCP endpoint, OS command injection through the Custom MCP Server feature, and vm2 sandbox escape via the overrideConfig option. Fixes are available in Flowise 2.1.4, 3.0.6 and 3.1.2.
Disclosed 20 June 2026 · Record updated 13 September 2026
Impact
Attackers can execute arbitrary OS commands on the Flowise host, leading to complete compromise of the platform container or server, plus denial of service, SSRF, prompt injection and data exfiltration in the overrideConfig case.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2024-58351
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-56274
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-71336
