ID:13072 - Exploit for Improper access control in Flowise - CVE-2026-56274
Published: September 14, 2026
Flowise
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the MCP command validation logic when processing custom MCP server command configurations. A remote user can supply a crafted command such as a docker build invocation to execute arbitrary code.
Exploitation requires a Flowise account or an API key with view and update permissions for chatflows, and the target environment must have the docker command available.