What is CVE-2026-69263?
The incomplete mitigation for CVE-2025-8943 in Flowise allows command injection via specially crafted environment variables, since `MCP/core.ts` only denies `PATH`, `LD_LIBRARY_PATH`, `DYLD_LIBRARY_PATH`, and `NODE_OPTIONS` by exact match while `-y`/`--yes` flags are blocked on `npx`. Versions prior to 3.1.3 are affected and should be updated immediately.
Azərbaycanca: Flowise LLM tətbiqində CVE-2025-8943 üçün tətbiq edilən zəifliyin aradan qaldırılması tam olmayıb – 'npx' əmrlərində `-y`/`--yes` bayraqları bloklansa da, `MCP/core.ts` faylında yalnız `PATH`, `LD_LIBRARY_PATH`, `DYLD_LIBRARY_PATH` və `NODE_OPTIONS` mühit dəyişənləri dəqiq adla rədd edilir; bu, xüsusi hazırlanmış mühit dəyişənləri vasitəsilə əmr inyeksiyasına imkan yarada bilər. 3.1.3 versiyasından əvvəlki versiyalar təsirlənir, dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of Flowise are affected by CVE-2026-69263?
CVE-2026-69263 affects all versions of Flowise prior to 3.1.3.
What type of attack does CVE-2026-69263 enable in Flowise?
This vulnerability allows command injection via specially crafted environment variables.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.