SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-91932

HIGH · CVSS 8.5 EPSS 0.82% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Flowise versions prior to 3.1.4 are vulnerable to a validation bypass in the MCP server configuration, enabling authenticated attackers to execute remote code by manipulating the unvalidated cwd parameter. This flaw allows attackers to bypass path validation and control the working directory, posing a significant risk of malicious code execution. Organizations using affected versions should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91932
Severity
HIGH
CVSS
8.5
EPSS
0.82%

Original NVD Description

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.