CVE-2026-40933Disclosure(flowiseai / flowise)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the input sanitization from the “Custom MCP” configuration in http://localhost:3000/canvas - where any user can add a new MCP, when doing so - adding a new MCP using stdio, the user can add any command, even though your code have input sanitization checks such as validateCommandInjection and validateArgsForLocalFileAccess, and a list of predefined specific safe commands - these commands, for example "npx" can be combined with code execution arguments ("-c touch /tmp/pwn") that enable direct code execution on the underlying OS. This vulnerability is fixed in 3.1.0.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 22 mentions across 16 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 12 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 21 signals
  • Disclosure: 10 classified signals
  • Peaked 4d ago at 3 mentions (2026-06-01); latest day: 1
  • 22 total mentions across 16 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline22 mentions / 16d
01223Mentions · 2026-04-16: 2Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-26: 2Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-28: 1Mentions · 2026-05-30: 2Mentions · 2026-05-31: 2Mentions · 2026-06-01: 3Mentions · 2026-06-05: 1Mentions · 2026-06-15: 1Mentions · 2026-06-21: 1Mentions · 2026-09-18: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-28: 1PoC Mentioned / Linked · 2026-05-30: 2PoC Mentioned / Linked · 2026-05-31: 2PoC Mentioned / Linked · 2026-06-01: 2PoC Mentioned / Linked · 2026-06-05: 1PoC Mentioned / Linked · 2026-06-15: 1Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-04-17: 1Exploit Tool / Code · 2026-05-30: 2Exploit Tool / Code · 2026-05-31: 2Exploit Tool / Code · 2026-06-01: 2Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-30: 2Technical Details · 2026-05-31: 2Technical Details · 2026-06-01: 3Technical Details · 2026-06-05: 1Technical Details · 2026-06-21: 1Technical Details · 2026-09-18: 104-1604-1704-1804-2104-2204-2604-2704-2905-2805-3005-3106-0106-0506-1506-2109-18
Signal classification4 categories
Disclosure
1045.5%
PoC
627.3%
Patch
313.6%
Exploit
313.6%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure2
2026-04-171
Patch1
2026-04-181
Disclosure1
2026-04-211
PoC1
2026-04-221
Disclosure1
2026-04-262
Disclosure2
2026-04-271
Patch1
2026-04-291
Patch1
2026-05-281
Disclosure1
2026-05-302
Exploit2
2026-05-312
Exploit1PoC1
2026-06-013
Disclosure1PoC2
2026-06-051
PoC1
2026-06-151
PoC1
2026-06-211
Disclosure1
2026-09-181
Disclosure1
Full discourse20 posts
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    🚨 CVE-2026-40933 Critical Vulnerability In Flowise! Remote Command Execution Via MCP Adapters! Bypassing Flowise's input sanitizer and executing code via "npx -c <command>" This is just one issue we found as part of the Anthropic MCP Supply Chain Vulnerability. Patch to the latest version of Flowise immediately! Read our blog for more details: https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/

    Post summary

    The advisory announces a critical remote command execution flaw in Flowise, details a PoC exploitation method via MCP adapters, and urges immediate patching.

    121102546
    1.1K followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Patch

    Flowise | CVE-2026-40933 | CVSS 10.0 Upsonic | CVE-2026-30625 | CVSS 9.8 As part of our MCP Supply Chain Vulnerability report which we published last week, we wrote a detailed explanation about our MCP STDIO input sanitization bypass techniques, and what can security engineers learn and implement from our research. Both platform implemented the recommended approach by Anthropic: input sanitization. But both missed a core behaviour of NPX - which allows the ability to pass '-c' and an arbitrary command, allowing direct command execution on the underlying machine. Even though special characters weren't allowed, passing '-' wasn't blocked as it's a valid character in most use cases. The best case for engineers is not to try and fight any user input - but to execute the MCP STDIO server inside an isolated sandbox. This would allow command execution, but removes the ability to read sensitive information and perform lateral movement. Read the full details in our blog - https://www.ox.security/blog/flowise-cve-2026-40933-upsonic-cve-2026-30625-what-to-do-when-best-practice-isnt-enough/

    Post summary

    The post highlights two high‑severity CVEs (Flowise and Upsonic), explains a bypass of NPX command sanitization, and recommends mitigating by sandboxing the MCP STDIO server; no PoC or active exploitation is reported.

    022632.9K
    505 followersView on X
  • SecurityWeek@SecurityWeek
    Exploit

    Exploit Code Published for Critical Flowise RCE Vulnerability - (CVE-2026-40933) - https://www.securityweek.com/exploit-code-published-for-critical-flowise-rce-vulnerability/

    Post summary

    Exploit code has been released for CVE‑2026‑40933, confirming a functional RCE exploit for Flowise, though no evidence of active use or patch information is provided.

    130411.5K
    228.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Flowise MCP RCE (CVE-2026-40933) Authenticated attackers can execute arbitrary OS commands via unsafe serialization in MCP adapters through malicious /canvas configurations. 👉 Fixed in 3.1.0 - update immediately &amp; restrict MCP access to trusted users

    Post summary

    The post announces a critical remote code execution vulnerability (CVE‑2026‑40933) in Flowise MCP, explains that authenticated users can run arbitrary OS commands via unsafe serialization, and urges an upgrade to 3.1.0 and access restriction.

    11070260
    229 followersView on X
  • yousukezan@yousukezan
    Disclosure

    AIエージェント構築基盤Flowiseに、細工された設定ファイルを読み込むだけで任意コード実行が可能になる脆弱性「CVE-2026-40933」が見つかった。報告者によると、悪意ある「chatflow」をインポートするだけでサーバー側コードが実行され、APIキーやクラウド認証情報などへアクセスされる恐れがある。 問題は、Flowiseの「Custom MCP Tool」が stdio ベースのMCP(Model Context Protocol)を利用し、ユーザー指定コマンドをサーバー上で子プロセスとして実行していた点にある。研究者は、共有chatflowに悪意あるMCP設定を埋め込むことで、読み込み時点で不正コマンドが自動実行されることを確認した。 Flowiseはコマンド制限や入力検証を追加したものの、研究者は npm_config_yes=true など環境変数を利用して回避可能だと指摘。「入力検証では根本問題を解決できない」として、stdio MCP を危険機能として無効化すべきだと主張している。 Flowise Cloudは影響を受けないが、セルフホスト版はデフォルトで脆弱な状態だという。対策として、研究者は CUSTOM_MCP_PROTOCOL=sse を設定し、stdio MCP を無効化するよう推奨している。 https://www.obsidiansecurity.com/blog/when-is-stdio-mcp-actually-a-vulnerability

    Post summary

    CVE‑2026‑40933 in Flowise permits arbitrary code execution via a malicious chatflow, with researchers confirming the exploit and advising users to disable stdio MCP as a workaround.

    000711.9K
    14.5K followersView on X
  • OX Security@OX__Security
    Patch

    🚨 critical MCP vulnerabilities: Flowise (CVE-2026-40933, 10.0) Upsonic (CVE-2026-30625, 9.8) Input sanitization ≠ security. Even following Anthropic guidance, NPX -c enabled arbitrary command execution. 💥 Result: host takeover FIX + FULL REPORT: https://www.ox.security/blog/flowise-cve-2026-40933-upsonic-cve-2026-30625-what-to-do-when-best-practice-isnt-enough/ https://t.co/k21ZhEEIOM

    Post summary

    The post highlights the discovery of critical vulnerabilities in Flowise and Upsonic (CVE-2026-40933 and CVE-2026-30625) that allow arbitrary command execution and host takeover, and supplies a full report with remediation and fix details.

    10142835
    357 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Obsidian Security discloses CVE-2026-40933 in self-hosted Flowise, one-click RCE via malicious chatflow imports exploiting unsafe stdio MCP config, CVSS 9.9. https://threatcluster.io/cluster/critical-rce-vulnerability-discovered-in-flowises-mcp-implem-26ae0fb8

    Post summary

    The post announces the discovery of CVE‑2026‑40933, a high‑severity remote code execution vulnerability in Flowise, detailing the exploitation vector and CVSS score.

    0200094
    291 followersView on X
  • 秋華@aliksir_mirage
    Patch

    mcp-yoshi v1.4.0 リリース。Flowise の CVE-2026-40933 (Critical 10.0/10) と同型攻撃クラスを Claude Code 上で検出可能にする MCP 通信フィルタです。 ▼ きっかけ 昨日 Anthropic researcher の igor-magun-wd 氏が Flowise の脆弱性 59件 を一斉公開。"Anthropic MCP Supply Chain Vulnerability" シリーズの一環。 中でも CVE-2026-40933 / GHSA-c9gw-hvqq-f33r は、Flowise の Custom MCP の入力サニタイザを `npx -c "touch /tmp/pwn"` で素通りさせる攻撃。allowlist が `['node', 'npx', 'python', 'python3', 'docker']` と「コマンド名のみ」で判定していたのが原因です。 ▼ 一般化した攻撃クラス 「信頼コマンド + 危険オプション」で大半のパッケージランナーが任意コード実行に化けます。 ・npx -c / --call ・npm exec -- <pkg> (npm v7+ セパレータ形式) ・pnpm exec -c, pnpm dlx -c ・yarn dlx -c ・bun x, bun -e, bun exec ・deno eval / -e / -p ・NODE_OPTIONS=--experimental-loader=data:text/javascript,... mcp-yoshi 既存の IN-002 (Shell Command Embedding) は python/node の -c/-e のみカバーで穴だったので、今回拡張しました。 ▼ 副次調査で6ルール追加 Flowise 59件 advisory を全網羅して、新規ルール 6 種を IN-015〜021 として実装: ・IN-015 Parameter Override (BLOCK): overrideConfig + 危険トークン同居 ・IN-017 Path Traversal (BLOCK): basePath/filePath への機密パス指定 ・IN-018 Query Injection (BLOCK + WARN分離): SQL/Cypher/NoSQL ・IN-019 Sandbox Escape (BLOCK): vm2 escape, constructor.constructor() ・IN-020 Header Spoofing (WARN): x-request-from: internal 等 ・IN-021 Browser Launch RCE (BLOCK): Puppeteer/Playwright executablePath にシェルバイナリ 合計、Flowise 59件のうち 76% (45件) を防御範囲化しました。 ▼ 横展開で見えた他ツールの穴 似た allowlist の罠が他にも: ・neko-harness-doctor IND-22: publisher は検証するが args フラグは未精査 ・claude-code-skill-security-check の http://validate-bash.sh Tier 5: python/node のみで npx エコシステム未カバー 各ツール側の対応は別タスクで起票予定。 ▼ インストール npm install -g mcp-yoshi 詳細: https://github.com/aliksir/mcp-yoshi/blob/master/CHANGELOG.md #MCP #ClaudeCode #npm #SupplyChainSecurity #infosec #SecurityResearch

    Post summary

    The post announces mcp‑yoshi v1.4.0, a mitigation tool that blocks CVE‑2026‑40933 by expanding input checks across many package runners, and outlines the exploitation vectors that prompted its development.

    00020168
    81 followersView on X
  • it security@it__security
    PoC

    Ein neu veröffentlichter Proof-of-Concept-Code für die Schwachstelle CVE-2026-40933 ermöglicht Angreifern die sofortige Übernahme von Flowise-Servern. https://www.it-daily.net/shortnews/flowise-server-kritischer-exploit

    Post summary

    The article announces that a new Proof‑of‑Concept code for CVE‑2026‑40933 is available, which would allow attackers to immediately take over Flowise servers. It links to an external source for more information.

    00010119
    5.3K followersView on X
  • Cyber_Lens@Aiz_Cyber
    PoC

    One Click. Full Server Compromise. ⚠️ A critical Flowise flaw (CVE-2026-40933) now has public exploit code, allowing attackers to achieve RCE through a malicious AI workflow import. Full breakdown 👇 #aiz_cyber #Flowise #AIsecurity https://t.co/4HWUbo6Qk9

    Post summary

    Public exploit code for CVE-2026-40933 is available, enabling remote code execution via malicious AI workflow imports; no patch or active exploitation reported.

    0001058
    34 followersView on X
  • CaptainAmericaTex@CaptAmericaTx
    Disclosure

    @PR0GRAMMERHUM0R Context: The Model Context Protocol allows AI LLMs to interface with external agents, and is currently implemented by major AI providers. On April 2026, researchers discovered flaw CVE-2026-40933 that allows anyone on the net, issue system commands (source: cloudsecuriyalliance).

    Post summary

    Researchers have identified CVE-2026-40933, a flaw in the Model Context Protocol that permits unauthenticated remote users to execute system commands.

    00010105
    131 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Authenticated RCE (CVE-2026-40933) affects `Flowise` via MCP Adapters, allowing arbitrary code execution. Assess exposure and monitor for official patches. #Flowise #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-40933-flowise-authenticated-rce

    Post summary

    The post announces CVE‑2026‑40933 as an authenticated RCE affecting Flowise, urges patch monitoring, and provides technical details but no PoC or exploit code.

    0001078
    12 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-40933: Flowise Authenticated Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04xVgsN0

    Post summary

    The text announces CVE-2026-40933 as an authenticated command injection vulnerability in Flowise and links to an external article. It identifies the vulnerability type but provides no exploit details, PoC, patch information, or active exploitation claims, functioning primarily as a vulnerability disclosure with a referral to full details.

    0000030
    34 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-40933: Flowise MCP Adapter RCE Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04m4_tM0

    Post summary

    The text announces a new remote code execution vulnerability (CVE‑2026‑40933) in the Flowise MCP Adapter and promises guidance on how to respond.

    0000040
    31 followersView on X
  • AI Security Engineers@aiseceng
    PoC

    PoC Drops for Flowise CVE-2026-40933 – RCE vulnerability could let attackers seize control, deepening security concerns! https://zpr.io/Y6XLjYqA3xF9 https://t.co/jhytID0vW8

    Post summary

    The tweet announces the release of a PoC for Flowise's CVE-2026-40933, highlighting an RCE vulnerability that could let attackers take control, but it does not detail exploitation or patching information.

    00000101
    6.8K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼ #FlowiseAI: disponibile un #PoC per lo sfruttamento della CVE-2026-40933 Rischio: 🟠 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/flowiseai-poc-pubblico-per-lo-sfruttamento-della-cve-2026-40933 ⚠ Importante mantenere aggiornati i sistemi https://t.co/55ckiXTLS6

    Post summary

    The tweet announces a publicly available PoC for CVE‑2026‑40933, a remote code execution vulnerability, and urges users to keep their systems up to date.

    0000057
    616 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Exploit

    ⚠️ AI開発ツール「Flowise」にサーバー乗っ取りの穴(CVE-2026-40933) Flowiseは、プログラミングせずに画面で部品をつないでAIチャットボットやエージェントを作れる人気ツール(GitHubスター5万超)。 その「AIの処理フロー定義ファイル(chatflow)」に細工ができる。攻撃者が“便利な設定だよ”と渡したファイルを、相手が自社サーバーに取り込む——たったそれだけで、攻撃者の好きなプログラムがそのサーバー上で動いてしまう。 結果、サーバー本体・保存された認証情報やAPIキー・つながっている他のクラウドサービスまで乗っ取られる恐れ。しかも攻撃の実証コード(PoC)はすでに公開済みで、悪用のハードルは下がっている。 ✅ やること ・自社サーバーでFlowiseを動かしているか確認 ・使っていれば v3.1.0 以上へアップデート ・出所のわからないchatflowは取り込まない ・可能なら管理画面をインターネットに直接公開しない ※クラウド版(Flowise Cloud)は影響なし 🔗 https://www.securityweek.com/exploit-code-published-for-critical-flowise-rce-vulnerability/ #セキュリティ #AI #サプライチェーン

    Post summary

    CVE‑2026‑40933 is a remote code execution flaw in Flowise’s chatflow files; an exploit PoC has been published, and the vendor recommends updating to v3.1.0+ to mitigate the risk.

    0000091
    45 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    PoC

    Obsidian Security published PoC code for CVE-2026-40933, a critical 9.9 RCE in Flowise. Crafted chatflow imports can trigger command execution in self-hosted deployments via Anthropic MCP. #Flowise #MCP #ObsidianSecurity https://ift.tt/H3ztMDd

    Post summary

    Obsidian Security released PoC code for CVE‑2026‑40933, a critical remote code execution flaw in Flowise. The post provides technical details but does not report active exploitation or a patch.

    00000252
    4.3K followersView on X
  • America's Pick@nims213
    Exploit

    Exploit Code Published for Critical Flowise RCE Vulnerability https://ift.tt/uPbMLg5 Obsidian Security has released technical information and proof-of-concept (PoC) code targeting a remote code execution (RCE) vulnerability in Flowise. The issue, tracked as CVE-2026-40933 (…

    Post summary

    Obsidian Security has released PoC and exploit code for the critical Flowise RCE vulnerability CVE-2026-40933; no evidence of current active exploitation or patch availability is mentioned.

    00000628
    1.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40933 Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adap… https://www.cve.org/CVERecord?id=CVE-2026-40933 ----- Traducción: CVE-2026-40933 Flo… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-40933, noting unsafe serialization in Flowise before v3.1.0, but it provides no PoC, exploit, active exploitation evidence, or patch information.

    0000043
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more