Code Injection in Flowise - #VU146558
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to manipulate LLM behavior and disclose sensitive information.
The vulnerability exists due to code injection in MCP tool descriptions passed into LangChain Tool objects when connecting to a malicious MCP server. A remote user can supply a poisoned MCP server description to manipulate LLM behavior and disclose sensitive information.
User interaction is required to configure Flowise to connect to the malicious MCP server.