Improper access control in Flowise - CVE-2026-56274
Published: May 18, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the MCP command validation logic when processing custom MCP server command configurations. A remote user can supply a crafted command such as a docker build invocation to execute arbitrary code.
Exploitation requires a Flowise account or an API key with view and update permissions for chatflows, and the target environment must have the docker command available.