๐Ÿ” CVE Alert

CVE-2026-91936

MEDIUM 6.8

Flowise before 3.1.4 Script Injection via Docker Workflows

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.

CWE CWE-78
Vendor flowiseai
Product flowise
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for flowiseai flowise

Be the first to know when new medium vulnerabilities affecting flowiseai flowise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

FlowiseAI / Flowise
0 < 3.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jrcq-qjw5-xx5q vulncheck.com: https://www.vulncheck.com/advisories/flowise-before-3.1.4-script-injection-via-docker-workflows

Credits

๐Ÿ” patrickputmansec