Eval Injection in Flowise - #VU140067

 

Eval Injection in Flowise - #VU140067

Published: July 30, 2026


Vulnerability identifier: #VU140067
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the Custom MCP node when spawning stdio-based MCP processes with user-controlled environment variables and commands. A remote user can supply a crafted Custom MCP configuration and trigger action refresh to execute arbitrary code.

Only deployments using the stdio Custom MCP protocol are vulnerable, and the issue can be triggered when refreshing the available actions for the Custom MCP node.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins