Critical RCE Vulnerability Discovered in Flowise's MCP Implementation

Critical RCE Vulnerability Discovered in Flowise's MCP Implementation

1 Jun 2026 Csoonlinewww.obsidiansecurity.com 87% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

Obsidian Security identified a critical one-click remote code execution (RCE) vulnerability in Flowise (CVE-2026-40933), affecting self-hosted deployments. The flaw allows attackers to execute arbitrary server-side code by importing malicious chatflows, compromising server environments and sensitive data. Flowise's stdio MCP configuration lacks proper sandboxing, enabling this exploit. Although Flowise Cloud is safe due to stdio MCP being disabled, self-hosted versions remain vulnerable. The current patch relies on input validation that can be easily bypassed, leaving systems at risk. This vulnerability has a CVSS score of 9.9, indicating near-max severity. Organizations using Flowise are urged to review their configurations and consider disabling stdio MCP to mitigate risks.

Key Points: • CVE-2026-40933 allows one-click RCE in self-hosted Flowise deployments. • The vulnerability stems from inadequate sandboxing in stdio MCP configurations. • Current patches are insufficient, relying on easily bypassed input validation.

ThreatCluster AI

Timeline

2025-12-05
CVE-2025-34291 published
Obsidian Security disclosed a critical account takeover and RCE vulnerability in Langflow, enabling full system compromise.
www.obsidiansecurity.com
2026-04-15
CVE-2026-30616 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-15
CVE-2026-30617 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-15
CVE-2026-30624 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-21
CVE-2026-40933 published
Obsidian Security reported a one-click RCE vulnerability in Flowise's MCP implementation, affecting self-hosted versions.
www.obsidiansecurity.com
2026-05-21
CISA adds CVE-2025-34291 to KEV
CISA included CVE-2025-34291 in its Known Exploited Vulnerabilities catalog, indicating active exploitation.
www.obsidiansecurity.com

Community

Browse all →