CVE-2026-58057
published 2026-06-28CVE-2026-58057: Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment…
PriorityP339medium5CVSS 3.1
AVNACHPRLUINSUCLILAL
EXPLOIT
EPSS
1.17%
64.0th percentile
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can thereby inject NODE_OPTIONS --require and execute arbitrary code in the Flowise server context.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| flowise | flowise | < 3.1.3 | 3.1.3 |
| flowiseai | flowise | < 3.1.3 | 3.1.3 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_oracle7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node
ghsa_unreviewed·2026-06-28
CVE-2026-58057 [LOW] CWE-178 Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can thereby inject NODE_OPTIONS --require and execute arbitrary code in the Flowise server context.
VulDB
Flowise up to 3.1.2 on Windows Environment Variable case sensitivity (EUVD-2026-39977)
vuldb·2026-06-28·CVSS 5.0
CVE-2026-58057 [MEDIUM] Flowise up to 3.1.2 on Windows Environment Variable case sensitivity (EUVD-2026-39977)
A vulnerability labeled as problematic has been found in Flowise up to 3.1.2 on Windows. This issue affects some unknown processing of the component Environment Variable Handler. Such manipulation leads to improper handling of case sensitivity.
This vulnerability is referenced as CVE-2026-58057. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.
Oracle
Oracle Oracle Communications Risk Matrix: Security (Netty) — CVE-2025-58057
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-58057 [MEDIUM] Oracle Oracle Communications Risk Matrix: Security (Netty) — CVE-2025-58057
Oracle Oracle Communications Risk Matrix: Security (Netty) vulnerability
CVE: CVE-2025-58057
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
No detection rules found.
No writeups or analysis indexed.
2026-06-28
Published