Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens. | |
| Title | Flowise before 3.1.4 Script Injection via Docker Workflows | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:17:59.008Z
Reserved: 2026-09-15T11:06:02.263Z
Link: CVE-2026-91936
No data.
Status : Received
Published: 2026-09-15T16:17:45.013
Modified: 2026-09-15T16:17:45.013
Link: CVE-2026-91936
No data.
OpenCVE Enrichment
Updated: 2026-09-15T20:15:14Z