Junglewise Threat Intelligence

CVE-2026-40933: Flowise Flowise authenticated RCE in MCP Adapters

CVE-2026-40933 · Severity: critical · CVSS 9.9 · Published 2026-04-16

Technologies: flowise (npm), FlowiseAI Flowise, flowise-components (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is an open-source tool used to build customized AI workflows and applications. A security vulnerability in its Model Context Protocol (MCP) adapter allows an authenticated user to execute arbitrary commands on the server hosting the application. This could lead to a complete system takeover, unauthorized access to sensitive AI models, or theft of corporate data.

Technical details

An OS command injection vulnerability (CWE-78) exists in Flowise due to improper neutralization of special elements in the Model Context Protocol (MCP) adapter. While the application implements some sanitization checks (such as validateCommandInjection), these can be bypassed by providing "safe" commands like 'npx' combined with malicious arguments (e.g., '-c'). An authenticated attacker with access to the canvas configuration can add a custom MCP using the stdio transport to execute arbitrary commands on the underlying operating system. The vulnerability is fixed in version 3.1.0.

Affected products

  • FlowiseAI flowise <= 3.0.13
  • FlowiseAI flowise-components <= 3.0.13

Timeline

  • 2026-04-15: disclosed
  • 2026-04-16: advisory: GHSA-c9gw-hvqq-f33r published
  • 2026-04-16: patched: Version 3.1.0 released

References

Related threats