CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73601

unknowncovered by 1 sourcefirst seen 2026-08-13
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment variables with python3, or leverage the root working directory with node to bypass validation and execute system commands.

⚡ Watch CVE-2026-73601

Get an email if CVE-2026-73601 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73601

CVE.org record

Embed the live status

CVE-2026-73601 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73601 status](https://www.csirts.com/badge/CVE-2026-73601)](https://www.csirts.com/cve/CVE-2026-73601)