Moshe Siman Tov Bustan[verified]@MosheTovDisclosure
The advisory announces a critical remote command execution flaw in Flowise, details a PoC exploitation method via MCP adapters, and urges immediate patching.
Moshe Siman Tov Bustan[verified]@MosheTovPatch
The post highlights two high‑severity CVEs (Flowise and Upsonic), explains a bypass of NPX command sanitization, and recommends mitigating by sandboxing the MCP STDIO server; no PoC or active exploitation is reported.
SecurityWeek[verified]@SecurityWeekExploit
Exploit code has been released for CVE‑2026‑40933, confirming a functional RCE exploit for Flowise, though no evidence of active use or patch information is provided.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces a critical remote code execution vulnerability (CVE‑2026‑40933) in Flowise MCP, explains that authenticated users can run arbitrary OS commands via unsafe serialization, and urges an upgrade to 3.1.0 and access restriction.
yousukezan[verified]@yousukezanDisclosure
CVE‑2026‑40933 in Flowise permits arbitrary code execution via a malicious chatflow, with researchers confirming the exploit and advising users to disable stdio MCP as a workaround.
OX Security[verified]@OX__SecurityPatch
The post highlights the discovery of critical vulnerabilities in Flowise and Upsonic (CVE-2026-40933 and CVE-2026-30625) that allow arbitrary command execution and host takeover, and supplies a full report with remediation and fix details.
ThreatCluster[verified]@threatclusterDisclosure
The post announces the discovery of CVE‑2026‑40933, a high‑severity remote code execution vulnerability in Flowise, detailing the exploitation vector and CVSS score.
秋華[verified]@aliksir_miragePatch
The post announces mcp‑yoshi v1.4.0, a mitigation tool that blocks CVE‑2026‑40933 by expanding input checks across many package runners, and outlines the exploitation vectors that prompted its development.