---
id: CVE-2026-91932
title: >-
  Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server
  configuration allowing authenticated attackers remote code execution through
  an unvalidated cwd parameter
summary: >-
  Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server
  configuration allowing authenticated attackers remote code execution through
  an unvalidated cwd parameter. Attackers can bypass path validation using clean
  fil…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: FlowiseAI
product: Flowise
affected:
  - Flowise < 3.1.4
  - Flowise < 3.1.4
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:17:00.597'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91932'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x7x8-95gh-42xm
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-via-cwd-parameter
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x7x8-95gh-42xm
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T16:05:43.454063Z'
ingestedAt: '2026-09-15T15:39:12.927Z'
epss: 0.00734
epssPercentile: 0.52358
---

## Overview

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
