THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73601 (HIGH 8.8) — Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse

[NVD] CVE-2026-73601 (HIGH 8.8) — Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse

mednvdPublished 2026-08-13

CVE-2026-73601 CVSS: 8.8 HIGH Published: 2026-08-13T12:17:24.353

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment variables with

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73601