
Flowise versions prior to 3.1.2 contain a critical remote code execution flaw tracked as CVE-2026-56274, scoring 9.9 on CVSS and enabling attackers to execute arbitrary commands on the host via the Custom MCP Server feature.
Post summary
The text announces CVE-2026-56274, detailing a high‑severity remote code execution flaw in Flowise versions before 3.1.2 via the Custom MCP Server feature, without mentioning PoC, exploit tools, active attacks, patches, or debunking.


