Critical Vulnerability in Flowise Allows Remote Command Execution via MCP Adapters
ID: 076ba0b7-8b20-5a79-ad6e-c6a4815c574e
STIX ID: report--076ba0b7-8b20-5a79-ad6e-c6a4815c574e
Feed Name: Cyber Press
A critical design flaw in Anthropic’s Model Context Protocol (MCP) enables remote command execution across MCP-based tools (including Flowise), affecting official SDKs (Python, Java, Rust, TypeScript) and creating broad supply-chain risk — researchers report millions of downloads, thousands of publicly accessible MCP servers, multiple CVEs across popular AI tools, and attack vectors such as unauthenticated UI injection and zero-click prompt injection; vendors and users are advised to restrict access, treat MCP inputs as untrusted, install verified components, sandbox services, and monitor for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
