Exploit Code Released for Critical Flowise LLM Platform RCE
TL;DR. Proof-of-concept code is now public for a critical remote code execution vulnerability in the Flowise LLM building platform. - Attackers can execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. - The flaw, CVE-2026-40933, results from a systemic command injection vulnerability in Anthropic's MCP protocol. - The weakness allowed any user to add a new MCP with arbitrary commands before Flowise version 3.1.0.
- Exploit code for Flowise RCE (CVE-2026-40933) is publicly available.
- Vulnerability allows remote code execution via malicious chatflow import.
- Root cause is a command injection in Anthropic's MCP protocol.
- Flowise versions before 3.1.0 are affected.
Sources
- Exploit Code Published for Critical Flowise RCE Vulnerability — securityweek.com