External risk intelligence

Flowise Remote Code Execution via Unvalidated CWD Parameter.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-91932

Flowise is a low-code platform for building LLM applications, typically deployed as a web application or API service. Because these services are often exposed to the internet or internal networks to facilitate integration with external tools and user access, the management and configuration interfaces are frequently reachable via standard web protocols.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Flowise, a platform used for building AI applications, that could allow an attacker to execute malicious code remotely. The issue stems from a validation bypass in how server configurations are handled.

  • Bypassed security check allows remote code execution.
  • Matters if you use Flowise for AI application development.
  • Confirm if your Flowise deployments are affected.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access could exploit this vulnerability by manipulating the `cwd` parameter within the MCP server configuration. This bypasses path validation, allowing the attacker to control the working directory and execute malicious code, potentially leading to remote code execution.

  • Authenticated access is required.
  • Bypass path validation via `cwd` parameter.
  • Achieve remote code execution.

Live Threat

Current exploitation, exposure, and threat context

Attackers could execute arbitrary code on systems running Flowise when an authenticated user interacts with a specially crafted configuration. This occurs when path validation for the `cwd` parameter in MCP server configurations is bypassed, allowing the attacker to control the working directory and inject malicious commands. The risk is present when the MCP server configuration is exposed to an attacker.

  • System configuration and code execution.
  • Path validation bypass via clean filenames.
  • Compromise of the underlying system.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and platform owners should prioritize identifying all Flowise deployments and assessing their business criticality and external reachability. Confirming the specific teams responsible for Flowise instances, such as application or infrastructure teams, is crucial for effective remediation planning.

  • Application owners should manage the issue.
  • Verify Flowise deployment reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a low-code platform designed for building applications powered by Large Language Models. It provides a visual interface for developers to create AI workflows and agents. Because it acts as an integration hub, it is typically deployed as a web application or API service, allowing users to connect various AI tools and data sources into a cohesive system.

What does CVE-2026-91932 mean?

This CVE describes a security weakness classified as Improper Input Validation (CWE-20). In Flowise, the system fails to correctly verify the 'cwd' (current working directory) parameter used in MCP server configurations. This flaw allows an attacker to bypass security checks intended to restrict file path access, ultimately enabling them to execute unauthorized code on the server hosting the application.

How can an attacker trigger this vulnerability?

To trigger the bug, an attacker must have authenticated access to the Flowise instance. They manipulate the MCP server configuration by providing crafted filenames in the 'args' array, which allows them to bypass path validation for the 'cwd' parameter. Simply having a standard Flowise installation does not trigger the bug; it requires an active, authenticated attempt to supply these malicious configuration parameters to the server.

Is my Flowise instance at risk?

According to Halo Surface Signal, Flowise is often exposed to the internet or internal networks to support integrations, making the management interface reachable via web protocols. If your instance is accessible to users—especially in shared or multi-tenant environments where authentication is required—you should treat this as a relevant risk, as the configuration interface is the primary target for this bypass.

What should I do to address CVE-2026-91932?

The immediate priority is to identify all Flowise deployments within your environment. Once mapped, confirm your current version and update to version 3.1.4 or later, which addresses the validation flaw. Engage your application or infrastructure teams to review the reachability of these instances and ensure that access controls are properly configured while you coordinate the necessary software updates.

References