External risk intelligence

Flowise Custom MCP Node RCE Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-91931

Flowise is a low-code platform for building LLM applications, which is commonly deployed as a web-based application or API service. These services are frequently exposed to the internet or internal networks to facilitate access for users and integration with other web services, making the application interface a likely point of public or network-wide exposure.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a critical vulnerability in Flowise, a platform for building AI applications. The issue, found in the Custom MCP node, allows authenticated users to execute arbitrary code on the server by manipulating specific parameters related to package execution. At a high level, this could potentially lead to unauthorized control over the server hosting the Flowise application.

  • Attackers can run unauthorized code on servers.
  • Protects against unauthorized code execution risks.
  • Confirm relevance and assess exposure to this risk.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access could exploit this vulnerability by providing specific npm package names within the `mcpServerConfig` parameter in the Custom MCP node. This allows them to execute arbitrary code on the Flowise server through the `npx` command, potentially leading to a compromise of the system.

  • Requires authenticated user access.
  • Triggers via crafted `mcpServerConfig` parameter.
  • Risks arbitrary code execution on server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow authenticated attackers to execute arbitrary code on the Flowise server by supplying npx package names in the mcpServerConfig parameter, when supported by the advisory.

  • Server code execution.
  • Supplying malicious npx package names.
  • Unauthorized server control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Flowise is a platform for building LLM applications, often deployed as a web service. Owners of applications using Flowise and the infrastructure or platform teams supporting these deployments should investigate this vulnerability. The first step is to locate all Flowise instances, assess their reachability and business criticality, identify the accountable owner for each instance, and then plan remediation based on the identified risk.

  • Identify Flowise application owners and infrastructure teams.
  • Verify Flowise instance reachability and business criticality.
  • Plan remediation actions based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a low-code software platform designed for building applications powered by Large Language Models (LLMs). It provides a visual interface for developers to create AI-driven workflows and typically runs as a web-based application or backend service that integrates with other tools.

How does CVE-2026-91931 create a security risk?

This vulnerability is classified as CWE-78, or OS Command Injection. It occurs because the software fails to properly sanitize input when processing configuration settings. By injecting specific commands into the Custom MCP node, an attacker can trick the server into running unauthorized software or system-level instructions.

What triggers this vulnerability in Flowise?

An attacker must be able to interact with the Custom MCP node configuration and provide a malicious string within the mcpServerConfig parameter. The vulnerability does not trigger if the user lacks authenticated access to the application, nor does it activate through standard, non-malicious usage of the node for legitimate configuration.

Is my Flowise instance at risk?

According to Halo Surface Signal, Flowise is often deployed as a web or API service, making it a likely target for network-based access. If your instance is reachable from the internet or exposed across broad internal networks, an authenticated attacker could potentially reach the vulnerable component to trigger code execution.

How should I respond to this vulnerability?

Your first step is to perform an inventory of all active Flowise deployments in your environment. Once identified, work with the relevant application owners to assess the network reachability of these instances. Prioritize updating the software to version 3.1.4 or later, which contains the necessary security improvements to mitigate this issue.

References