THREAT OPS › Threat News › [NVD] CVE-2026-73601 (HIGH 8.8) — Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse
[NVD] CVE-2026-73601 (HIGH 8.8) — Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse
CVE-2026-73601 CVSS: 8.8 HIGH Published: 2026-08-13T12:17:24.353
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment variables with
Indicators of compromise
- CVE-2026-73601cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73601