CVE-2026-56274Disclosure(flowiseai / flowise)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for example, 'docker build' is not blocked, and 'npx --yes' is not blocked while only '-y' is) and the validateArgsForLocalFileAccess checks, resulting in execution of arbitrary commands on the Flowise host.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-23); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-07-16: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-16: 106-2306-2407-16
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-231
General1
2026-06-241
Disclosure1
2026-07-161
Disclosure1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Disclosure

    Flowise versions prior to 3.1.2 contain a critical remote code execution flaw tracked as CVE-2026-56274, scoring 9.9 on CVSS and enabling attackers to execute arbitrary commands on the host via the Custom MCP Server feature.

    Post summary

    The text announces CVE-2026-56274, detailing a high‑severity remote code execution flaw in Flowise versions before 3.1.2 via the Custom MCP Server feature, without mentioning PoC, exploit tools, active attacks, patches, or debunking.

    10000133
    396 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-56274: Flowise OS Command Injection Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04pQpgG0

    Post summary

    The article announces a newly identified OS command injection flaw in Flowise, discusses its business implications, and offers broad response guidance.

    0000042
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-56274 OS Command Injection in Flowise Before 3.1.2 Custom MCP Server Fe... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56274 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE-2026-56274 as an OS Command Injection vulnerability in Flowise before 3.1.2, but offers no PoC, exploit, or patch information.

    00000107
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more