Flowise AI Platform Vulnerable to Remote Code Execution

Security researchers at Obsidian Security discovered a critical vulnerability in Flowise, an open-source AI platform used by enterprises for self-hosted AI applications. The flaw, tracked as CVE-2026-40933, allows attackers to execute arbitrary commands through malicious Model Context Protocol (MCP) configurations. The vulnerability can be triggered with a single click via importing a malicious chatflow, requiring only post-authentication access. Flowise, commonly used for building AI assistants, chatbots, and autonomous agents, is vulnerable when stdio MCP is enabled. Flowise Cloud users are unaffected as the feature is disabled there. The official patch has proven insufficient, as attackers can bypass input validation. Organizations using self-hosted Flowise deployments should review their MCP server configurations immediately to mitigate risks. Source: SecurityWeek.
Read the full story
Original reporting by RSS: CSO Online. We only summarise โ never republish.