Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
UnratedPublic exploit

OS Command Injection in Flowise Custom MCP Server

IdentifiersCVE-2026-56274CWE-78

CVE-2026-56274 is a remote code execution vulnerability affecting Flowise before version 3.1.2 in the Custom MCP Server feature. The issue is caused by multiple OS command injection flaws arising from incomplete command-flag validation in the validateCommandFlags logic and a regex bypass in validateArgsForLocalFileAccess. According to the provided content, an attacker can configure a malicious MCP server that bypasses the intended restrictions, including cases where dangerous command patterns such as 'docker build' are not blocked and 'npx --yes' is permitted while only '-y' is filtered. By abusing these validation weaknesses, an authenticated attacker can cause arbitrary operating system commands to be executed on the Flowise host.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation results in arbitrary command execution on the underlying Flowise host. This can enable full compromise of the application environment, including unauthorized access to data handled by Flowise, modification of application state or chatflows, installation of additional tooling or malware, lateral movement from the host, and disruption of service availability. The provided content characterizes the issue as remotely exploitable and critical under CVSS v3.1.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by disabling or restricting use of the Custom MCP Server feature, limiting who can create or modify chatflows and MCP server configurations, and restricting API credentials that have view/update permissions for chatflows. Monitor for suspicious MCP server definitions and unexpected process execution on the Flowise host. These are compensating controls only; the primary fix is upgrading to 3.1.2 or later.

Remediation

Patch, then assume compromise.

Upgrade Flowise to version 3.1.2 or later. The provided content also indicates that remediation should include correcting the command validation logic in the Custom MCP Server feature, specifically strengthening validateCommandFlags and eliminating the regex bypass in validateArgsForLocalFileAccess. MCP server configuration handling should be hardened to reject malicious command and argument combinations, and chatflow management permissions should be reviewed and restricted to only trusted users and API clients.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity1

Community discussion across Reddit, Mastodon, and other social sources.