Code Injection in Flowise - #VU146558

 

Code Injection in Flowise - #VU146558

Published: September 1, 2026


Vulnerability identifier: #VU146558
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to manipulate LLM behavior and disclose sensitive information.

The vulnerability exists due to code injection in MCP tool descriptions passed into LangChain Tool objects when connecting to a malicious MCP server. A remote user can supply a poisoned MCP server description to manipulate LLM behavior and disclose sensitive information.

User interaction is required to configure Flowise to connect to the malicious MCP server.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins