
Upwind Security MDR@UpwindMDR
🚨High - Flowise Custom MCP Node npx Package RCE (CVE-2026-91931) Flowise's Custom MCP node mishandles the mcpServerConfig parameter, allowing authenticated attackers to supply arbitrary npx package names. The server invokes npx with attacker-controlled npm packages, resulting in remote code execution. 👉Affected: flowise / flowise-components < 3.1.4 | Upgrade to 3.1.4
1000073
303 followersView on X
