CVE-2026-73601 | FlowiseAI Flowise up to 3.1.2 Custom MCP node PYTHONWARNINGS/BROWSER os command injection
A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been classified as critical. The affected element is an unknown function of the component Custom MCP node. Performing a manipulation of the argument PYTHONWARNINGS/BROWSER results in os command injection.
This vulnerability was named CVE-2026-73601. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More