High severity8.8NVD Advisory· Published Aug 13, 2026· Updated Sep 4, 2026
CVE-2026-73601
CVE-2026-73601
Description
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment variables with python3, or leverage the root working directory with node to bypass validation and execute system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-g98q-rm45-q9h8nvdVendor Advisory
- www.vulncheck.com/advisories/flowise-before-remote-code-execution-via-custom-mcpnvdThird Party Advisory
News mentions
2- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- Flowise: Ten RCE and Data Exposure Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 13, 2026