Flowise MCP Server Remote Code Execution

zetlyn/cve-metasploit exploit cve CVE-2026-56274 known 2026-06-23

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/flowise_mcp_rce.rb

Properties

platformUnix
receipt
Source
Metasploit exploit modules
Its words
Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "cn-panda",
    "ABDUL JAFAROV <https://github.com/jafarov007>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n          through the Custom MCP (Model Context Protocol) node configuration.\n\n          The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n          which accepts arbitrary command and argument configurations for MCP server\n          initialization. An authenticated attacker can abuse the npx --yes flag to\n          fetch and execute a malicious npm package from an attacker-controlled HTTP\n          server, achieving arbitrary command execution on the Flowise host.\n\n          This module creates a malicious npm package tar archive in memory, serves it\n          via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n          to download and execute the package via npx.\n\n          To interact with the obtained shell, use the command: sessions -i <id>\n          (for example: sessions -i 1).",
  "disclosure_date": "2026-06-23",
  "fullname": "exploit/multi/http/flowise_mcp_rce",
  "is_install_path": true,
  "mod_time": "2026-08-20 18:02:33 +0000",
  "name": "Flowise MCP Server Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/flowise_mcp_rce",
  "references": [
    "CVE-2026-56274",
    "CWE-78",
    "GHSA-GHSA-m99r-2hxc-cp3q"
  ],
  "rport": 3000,
  "session_types": false,
  "targets": [
    "Unix Command"
  ],
  "type": "exploit"
}
rank600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 15:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "cn-panda",
    "ABDUL JAFAROV <https://github.com/jafarov007>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n          through the Custom MCP (Model Context Protocol) node configuration.\n\n          The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n          which accepts arbitrary command and argument configurations for MCP server\n          initialization. An authenticated attacker can abuse the npx --yes flag to\n          fetch and execute a malicious npm package from an attacker-controlled HTTP\n          server, achieving arbitrary command execution on the Flowise host.\n\n          This module creates a malicious npm package tar archive in memory, serves it\n          via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n          to download and execute the package via npx.\n\n          To interact with the obtained shell, use the command: sessions -i <id>\n          (for example: sessions -i 1).",
  "disclosure_date": "2026-06-23",
  "fullname": "exploit/multi/http/flowise_mcp_rce",
  "is_install_path": true,
  "mod_time": "2026-08-20 18:02:33 +0000",
  "name": "Flowise MCP Server Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/flowise_mcp_rce",
  "references": [
    "CVE-2026-56274",
    "CWE-78",
    "GHSA-GHSA-m99r-2hxc-cp3q"
  ],
  "rport": 3000,
  "session_types": false,
  "targets": [
    "Unix Command"
  ],
  "type": "exploit"
}

Text

Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution through the Custom MCP (Model Context Protocol) node configuration. The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint, which accepts arbitrary command and argument configurations for MCP server initialization. An authenticated attacker can abuse the npx --yes flag to fetch and execute a malicious npm package from an attacker-controlled HTTP server, achieving arbitrary command execution on the Flowise host. This module creates a malicious npm package tar archive in memory, serves it via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint to download and execute the package via npx. To interact with the obtained shell, use the command: sessions -i <id> (for example: sessions -i 1).