logo

Critical Flowise Flaw Gives Attackers Full Server Control

ID: 6b832f5f-2328-5fbd-87d7-a68c89fd0f11

STIX ID: report--6b832f5f-2328-5fbd-87d7-a68c89fd0f11

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

...
...

A critical remote-code-execution flaw (CVE-2026-40933) in the open-source Flowise AI workflow platform allows an attacker to run arbitrary commands on self-hosted servers simply by getting a logged-in user to import a malicious chatflow; a public PoC exists and the vendor's input-validation patch can be bypassed. Managed Flowise Cloud is not affected; recommended mitigations are disabling the Custom MCP stdio transport (use SSE) and treating imported MCP configurations as code from trusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.