CVE-2026-30625Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable execution of arbitrary OS commands. Maliciously crafted MCP tasks may lead to remote code execution with the privileges of the Upsonic process. In version 0.72.0 Upsonic added a warning about using Stdio servers being able to execute commands directly on the machine.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-16); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-18: 1Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1PoC Mentioned / Linked · 2026-04-27: 1Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-18: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-29: 104-1604-1804-2704-29
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure2
2026-04-181
Disclosure1
2026-04-271
Patch1
2026-04-291
Disclosure1
Full discourse5 posts
  • Moshe Siman Tov Bustan@MosheTov
    Patch

    Flowise | CVE-2026-40933 | CVSS 10.0 Upsonic | CVE-2026-30625 | CVSS 9.8 As part of our MCP Supply Chain Vulnerability report which we published last week, we wrote a detailed explanation about our MCP STDIO input sanitization bypass techniques, and what can security engineers learn and implement from our research. Both platform implemented the recommended approach by Anthropic: input sanitization. But both missed a core behaviour of NPX - which allows the ability to pass '-c' and an arbitrary command, allowing direct command execution on the underlying machine. Even though special characters weren't allowed, passing '-' wasn't blocked as it's a valid character in most use cases. The best case for engineers is not to try and fight any user input - but to execute the MCP STDIO server inside an isolated sandbox. This would allow command execution, but removes the ability to read sensitive information and perform lateral movement. Read the full details in our blog - https://www.ox.security/blog/flowise-cve-2026-40933-upsonic-cve-2026-30625-what-to-do-when-best-practice-isnt-enough/

    Post summary

    The post discloses two high‑CVSS vulnerabilities, explains the bypass technique, and recommends sandbox isolation as a mitigation, indicating a patch/workaround focus.

    022632.9K
    505 followersView on X
  • OX Security@OX__Security
    Disclosure

    🚨 critical MCP vulnerabilities: Flowise (CVE-2026-40933, 10.0) Upsonic (CVE-2026-30625, 9.8) Input sanitization ≠ security. Even following Anthropic guidance, NPX -c enabled arbitrary command execution. 💥 Result: host takeover FIX + FULL REPORT: https://www.ox.security/blog/flowise-cve-2026-40933-upsonic-cve-2026-30625-what-to-do-when-best-practice-isnt-enough/ https://t.co/k21ZhEEIOM

    Post summary

    The tweet announces critical vulnerabilities in Flowise and Upsonic, highlighting arbitrary command execution leading to host takeover; a full report is linked, but no exploit code or active exploitation is described.

    10142835
    357 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30625 Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arb… https://www.cve.org/CVERecord?id=CVE-2026-30625

    Post summary

    A new remote code execution vulnerability has been disclosed for Upsonic 0.71.6 (CVE‑2026‑30625), affecting its MCP task creation feature, with no PoC, exploit code, or patch yet mentioned.

    000101.4K
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical RCE vulnerability (CVE-2026-30625) affects `Upsonic`'s MCP server/task creation functionality, allowing arbitrary code execution. Restrict network access to mitigate risk. #RCE #Vulnerability #Infosec https://www.pulsepatch.io/posts/cve-2026-30625-upsonic-rce

    Post summary

    The post discloses a critical RCE flaw in Upsonic’s MCP server/task creation feature and recommends restricting network access to mitigate the risk.

    0000076
    12 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30625 Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arb… https://www.cve.org/CVERecord?id=CVE-2026-30625 ----- Traducción: CVE-2026-30625 Ups… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑30625, describing a remote code execution flaw in Upsonic 0.71.6’s MCP task creation, but provides no PoC, exploit, or patch information.

    0000040
    71 followersView on X

Explore more