CVE-2026-73601 | FlowiseAI Flowise up to 3.1.2 Custom MCP node PYTHONWARNINGS/BROWSER os command injection

SecurityVulns

A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been classified as critical. The affected element is an unknown function of the component Custom MCP node. Performing a manipulation of the argument PYTHONWARNINGS/BROWSER results in os command injection.

This vulnerability was named CVE-2026-73601. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More