{"id":"CVE-2026-91932","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-91932","generatedAt":"2026-09-20T10:52:18.726Z","title":"Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter.","description":"Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.","published":"2026-09-15T16:17:44.000Z","lastModified":"2026-09-16T20:17:01.000Z","status":"Awaiting Analysis","sourceIdentifier":"disclosure@vulncheck.com","cvss":{"version":"4.0","score":9,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M"},"cwe":["CWE-20"],"affected":[],"epss":{"score":0.00822,"percentile":0.55738,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"high","text":"High impact if exploited, but EPSS currently rates exploitation as unlikely (0.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit."},"changes":[],"references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x7x8-95gh-42xm","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/flowise-before-3.1.4-remote-code-execution-via-cwd-parameter","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x7x8-95gh-42xm","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-91932","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}