Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters
ID: 9e200338-dbc4-58a8-bd88-ee10fe542621
STIX ID: report--9e200338-dbc4-58a8-bd88-ee10fe542621
Feed Name: cybersecurityNews.com
OX Security disclosed a critical architectural vulnerability in the Model Context Protocol (MCP) used across multiple AI SDKs that enables remote code execution and broad supply-chain-style exposure. Researchers demonstrated live exploitations on production platforms (including Flowise), registry poisoning, and multiple attack families; the issue affects hundreds of thousands of instances and millions of downloads, several CVEs have been issued, and immediate mitigations and patching are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
