Eval Injection in Flowise - #VU140067
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the Custom MCP node when spawning stdio-based MCP processes with user-controlled environment variables and commands. A remote user can supply a crafted Custom MCP configuration and trigger action refresh to execute arbitrary code.
Only deployments using the stdio Custom MCP protocol are vulnerable, and the issue can be triggered when refreshing the available actions for the Custom MCP node.