logo

Critical Vulnerability in Flowise Allows Remote Command Execution via MCP Adapters

ID: 076ba0b7-8b20-5a79-ad6e-c6a4815c574e

STIX ID: report--076ba0b7-8b20-5a79-ad6e-c6a4815c574e

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-17

Author: AnuPriya

...
...

A critical design flaw in Anthropic’s Model Context Protocol (MCP) enables remote command execution across MCP-based tools (including Flowise), affecting official SDKs (Python, Java, Rust, TypeScript) and creating broad supply-chain risk — researchers report millions of downloads, thousands of publicly accessible MCP servers, multiple CVEs across popular AI tools, and attack vectors such as unauthenticated UI injection and zero-click prompt injection; vendors and users are advised to restrict access, treat MCP inputs as untrusted, install verified components, sandbox services, and monitor for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.