CRITICAL 9.0 NVD
CVE-2026-91931
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supp
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vcwp-f9rq-3887
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-via-custom
This critical severity vulnerability with a CVSS score of 9.0 was published on 2026-09-15 via NVD.
Risk Timeline
CVE Disclosed2026-09-15 · -1 days ago
Remediation Resources
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.