Critical severity9.9NVD Advisory· Published Jun 23, 2026· Updated Jun 25, 2026
CVE-2026-56274
CVE-2026-56274
Description
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for example, 'docker build' is not blocked, and 'npx --yes' is not blocked while only '-y' is) and the validateArgsForLocalFileAccess checks, resulting in execution of arbitrary commands on the Flowise host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-m99r-2hxc-cp3qnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/flowise-remote-code-execution-via-mcp-security-bypass-in-validatecommandflags-and-validateargsforlocalfileaccessnvdThird Party Advisory
News mentions
1- Flowise: Nine Vulnerabilities Including RCE and SSRF Disclosed in BatchVypr Intelligence · Jun 23, 2026