What is CVE-2026-73601?
A remote code execution vulnerability exists in Flowise versions before 3.1.3 within the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio. This flaw allows authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Immediate update to version 3.1.3 is strongly recommended.
Azərbaycanca: Flowise proqramının 3.1.3-dən əvvəlki versiyalarında "Custom MCP" node-da uzaqdan kod icrası (RCE) zəifliyi aşkarlanıb. Bu boşluq, "CUSTOM_MCP_PROTOCOL" parametri "stdio" olaraq təyin edildikdə, autentifikasiyadan keçmiş istifadəçilərə ətraf mühit dəyişənlərini manipulyasiya edərək özbaşına əmrlər icra etməyə imkan verir. Təcili olaraq Flowise-ni 3.1.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Flowise
FAQ2
Which versions of Flowise are affected by CVE-2026-73601?
This RCE vulnerability affects Flowise versions prior to 3.1.3.
Is authentication required to exploit CVE-2026-73601?
Yes, exploitation of this vulnerability requires an authenticated user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.