Improper access control in Flowise - #VU129618
Published: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in the Custom MCP feature when handling requests to load custom MCP server configurations. A remote attacker can send a specially crafted request to execute arbitrary code.
By default, installations may operate without authentication unless credentials are explicitly configured.