Skip to content

MCPA-2026-0006

highrce-vectors

Flowise MCP environment-variable blocklist bypass via npm_config_yes (unauthenticated RCE, CVE-2026-69263)

Flowise <= 3.1.2 shipped a mitigation for CVE-2025-8943 that blocks the -y/--yes flags on npx-launched MCP servers, but its environment-variable check denies only four names by exact match. npm reads configuration from npm_config_* environment variables, so setting npm_config_yes=true reproduces --yes: npx auto-installs and executes an attacker-named package, fully bypassing the mitigation even with the MCP security check enabled. Fixed in flowise / flowise-components 3.1.3.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.3
npmflowise-components
>= 0, < 3.1.3

Identifiers

CVE-2026-69263GHSA-xc48-889x-5qmwCWE-184

References

Timeline

  • Published: 2026-08-04

← All advisories