Critical Remote Code Execution Flaw Discovered in Flowise MCP Server
ID: d0299bb1-5a2f-53cd-80f6-f22607283ba7
STIX ID: report--d0299bb1-5a2f-53cd-80f6-f22607283ba7
Feed Name: ThreatCluster
Threat Score
Flowise disclosed CVE-2026-56274, a critical remote code execution vulnerability in the Custom MCP Server present in versions before 3.1.2. The flaw enables attackers with any Flowise account role or API access to configure a malicious MCP server and achieve arbitrary command execution on the host; it carries a CVSS 9.9 rating, has identified bypass techniques, and organisations are urged to upgrade to 3.1.2 and audit MCP server settings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
