logo

Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters

ID: 9e200338-dbc4-58a8-bd88-ee10fe542621

STIX ID: report--9e200338-dbc4-58a8-bd88-ee10fe542621

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-04-21

Author: Abinaya

...
...

OX Security disclosed a critical architectural vulnerability in the Model Context Protocol (MCP) used across multiple AI SDKs that enables remote code execution and broad supply-chain-style exposure. Researchers demonstrated live exploitations on production platforms (including Flowise), registry poisoning, and multiple attack families; the issue affects hundreds of thousands of instances and millions of downloads, several CVEs have been issued, and immediate mitigations and patching are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.