---
id: CVE-2026-91931
title: >-
  Flowise before 3.1.4 contains a remote code execution vulnerability in the
  Custom MCP node that allows authenticated attackers to execute arbitrary code
  by supplying npx package names in the mcpServerConfig parameter
summary: >-
  Flowise before 3.1.4 contains a remote code execution vulnerability in the
  Custom MCP node that allows authenticated attackers to execute arbitrary code
  by supplying npx package names in the mcpServerConfig parameter. Attackers can
  invok…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: FlowiseAI
product: Flowise
affected:
  - Flowise < 3.1.4
  - Flowise < 3.1.4
published: '2026-09-15'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:47.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91931'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vcwp-f9rq-3887
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-via-custom-mcp-npx
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vcwp-f9rq-3887
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00675
epssPercentile: 0.50141
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T14:49:25.987658Z'
ingestedAt: '2026-09-15T15:39:12.925Z'
---

## Overview

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
