logo

Critical Remote Code Execution Flaw Discovered in Flowise MCP Server

ID: d0299bb1-5a2f-53cd-80f6-f22607283ba7

STIX ID: report--d0299bb1-5a2f-53cd-80f6-f22607283ba7

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

Flowise disclosed CVE-2026-56274, a critical remote code execution vulnerability in the Custom MCP Server present in versions before 3.1.2. The flaw enables attackers with any Flowise account role or API access to configure a malicious MCP server and achieve arbitrary command execution on the host; it carries a CVSS 9.9 rating, has identified bypass techniques, and organisations are urged to upgrade to 3.1.2 and audit MCP server settings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.