CVE-2026-69263 | FlowiseAI Flowise up to 3.1.2 MCP Server core.ts os command injection

SecurityVulns

A vulnerability classified as critical has been found in FlowiseAI Flowise up to 3.1.2. This issue affects some unknown processing of the file packages/components/nodes/tools/MCP/core.ts of the component MCP Server. The manipulation leads to os command injection.

This vulnerability is referenced as CVE-2026-69263. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More