Junglewise Threat Intelligence

CVE-2026-41268: Flowise: Parameter Override Bypass Remote Command Execution

CVE-2026-41268 · Severity: high · CVSS 7.7 · Published 2026-04-16

Technologies: flowise (npm), flowise-components (npm). Vendors: Flowise, npm.

Executive brief

Flowise is an AI workflow orchestration platform that allows users to build and deploy chatflows. A critical unauthenticated remote code execution vulnerability enables attackers to execute arbitrary system commands on Flowise instances by bypassing validation checks and injecting malicious environment variables. This impacts any production deployment with API Override enabled and public chatflows containing MCP tool nodes.

Technical details

The vulnerability stems from two chained flaws in Flowise. First, the FILE-STORAGE:: validation in the replaceInputsWithConfig function (packages/server/src/utils/index.ts) uses .includes() instead of .startsWith(), allowing attackers to embed the keyword anywhere in a parameter string to bypass authorization checks for any parameter, including mcpServerConfig. Second, the Custom MCP node's environment variable blocklist does not include NODE_OPTIONS, permitting attackers to inject this variable with --experimental-loader flags to execute arbitrary JavaScript code before process startup. Exploitation requires API Override to be enabled and the chatflow to be publicly accessible, but needs no authentication or prior knowledge of the target. The attack succeeds through a single HTTP request and was patched in version 3.1.0 (affecting versions ≤3.0.13).

Affected products

  • Flowise Flowise <=3.0.13
  • Flowise flowise-components <=3.0.13

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: patched: Version 3.1.0 patched

References

Related threats