CVE-2026-91936: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in FlowiseAI Flowise
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
AI Analysis
Technical Summary
CVE-2026-91936 describes an OS command injection vulnerability in FlowiseAI Flowise versions prior to 3.1.4. The vulnerability arises from improper neutralization of special elements in workflow_dispatch inputs such as tag_version and node_version, which are directly interpolated into shell run blocks during Docker image build workflows. This allows an attacker with repository write access to inject shell metacharacters and execute arbitrary commands. The impact includes potential theft of sensitive credentials like AWS credentials and Docker Hub tokens. The vulnerability has a CVSS 3.1 score of 6.8 (medium severity) with network attack vector, low attack complexity, high privileges required, no user interaction, and a scope change with no confidentiality impact but high integrity impact and no availability impact. A patch is available and should be applied.
Potential Impact
An attacker with repository write access can exploit this vulnerability to execute arbitrary OS commands within the Docker image build process. This can lead to theft of sensitive credentials such as AWS credentials and Docker Hub tokens, compromising the integrity of the affected environment. There is no reported impact on confidentiality or availability beyond the credential theft risk.
Mitigation Recommendations
A patch is available for FlowiseAI Flowise that fixes this vulnerability in version 3.1.4. Users should upgrade to version 3.1.4 or later to remediate this issue. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor advisory for confirmation. Until patched, restrict repository write access to trusted users only to reduce risk.
CVE-2026-91936: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in FlowiseAI Flowise
Description
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
CVSS v3.1
Score 6.8medium
Affected software
FlowiseAI
Flowise
pkg:github/flowiseai/FlowiseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91936 describes an OS command injection vulnerability in FlowiseAI Flowise versions prior to 3.1.4. The vulnerability arises from improper neutralization of special elements in workflow_dispatch inputs such as tag_version and node_version, which are directly interpolated into shell run blocks during Docker image build workflows. This allows an attacker with repository write access to inject shell metacharacters and execute arbitrary commands. The impact includes potential theft of sensitive credentials like AWS credentials and Docker Hub tokens. The vulnerability has a CVSS 3.1 score of 6.8 (medium severity) with network attack vector, low attack complexity, high privileges required, no user interaction, and a scope change with no confidentiality impact but high integrity impact and no availability impact. A patch is available and should be applied.
Potential Impact
An attacker with repository write access can exploit this vulnerability to execute arbitrary OS commands within the Docker image build process. This can lead to theft of sensitive credentials such as AWS credentials and Docker Hub tokens, compromising the integrity of the affected environment. There is no reported impact on confidentiality or availability beyond the credential theft risk.
Mitigation Recommendations
A patch is available for FlowiseAI Flowise that fixes this vulnerability in version 3.1.4. Users should upgrade to version 3.1.4 or later to remediate this issue. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor advisory for confirmation. Until patched, restrict repository write access to trusted users only to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-15T11:06:02.263Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6aa9651a55bf5e2cf502eb02
Added to database: 09/15/2026, 15:32:42 UTC
Last enriched: 09/15/2026, 16:02:23 UTC
Last updated: 09/16/2026, 03:23:42 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.