CVE-2026-69263Flowiseai · Flowise
Vulnerability data via NVD (ingested)
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install and execute the named package when a Custom MCP server launched. This issue is fixed in version 3.1.3.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-69263product:"Flowiseai Flowise"http.html:"Flowise"More intel sources (5)
vuln:CVE-2026-69263vulnerabilities.cve_id: CVE-2026-69263CVE-2026-69263CVE-2026-69263"CVE-2026-69263" exploit -site:nvd.nist.gov