Flowise MCP Server Remote Code Execution
zetlyn/cve-metasploit exploit cve CVE-2026-56274 known 2026-06-23
Properties
| platform | Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"cn-panda",
"ABDUL JAFAROV <https://github.com/jafarov007>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n through the Custom MCP (Model Context Protocol) node configuration.\n\n The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n which accepts arbitrary command and argument configurations for MCP server\n initialization. An authenticated attacker can abuse the npx --yes flag to\n fetch and execute a malicious npm package from an attacker-controlled HTTP\n server, achieving arbitrary command execution on the Flowise host.\n\n This module creates a malicious npm package tar archive in memory, serves it\n via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n to download and execute the package via npx.\n\n To interact with the obtained shell, use the command: sessions -i <id>\n (for example: sessions -i 1).",
"disclosure_date": "2026-06-23",
"fullname": "exploit/multi/http/flowise_mcp_rce",
"is_install_path": true,
"mod_time": "2026-08-20 18:02:33 +0000",
"name": "Flowise MCP Server Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/flowise_mcp_rce",
"references": [
"CVE-2026-56274",
"CWE-78",
"GHSA-GHSA-m99r-2hxc-cp3q"
],
"rport": 3000,
"session_types": false,
"targets": [
"Unix Command"
],
"type": "exploit"
} |
|---|---|
| rank | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"cn-panda",
"ABDUL JAFAROV <https://github.com/jafarov007>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n through the Custom MCP (Model Context Protocol) node configuration.\n\n The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n which accepts arbitrary command and argument configurations for MCP server\n initialization. An authenticated attacker can abuse the npx --yes flag to\n fetch and execute a malicious npm package from an attacker-controlled HTTP\n server, achieving arbitrary command execution on the Flowise host.\n\n This module creates a malicious npm package tar archive in memory, serves it\n via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n to download and execute the package via npx.\n\n To interact with the obtained shell, use the command: sessions -i <id>\n (for example: sessions -i 1).",
"disclosure_date": "2026-06-23",
"fullname": "exploit/multi/http/flowise_mcp_rce",
"is_install_path": true,
"mod_time": "2026-08-20 18:02:33 +0000",
"name": "Flowise MCP Server Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/flowise_mcp_rce",
"references": [
"CVE-2026-56274",
"CWE-78",
"GHSA-GHSA-m99r-2hxc-cp3q"
],
"rport": 3000,
"session_types": false,
"targets": [
"Unix Command"
],
"type": "exploit"
} |
Text
Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution
through the Custom MCP (Model Context Protocol) node configuration.
The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,
which accepts arbitrary command and argument configurations for MCP server
initialization. An authenticated attacker can abuse the npx --yes flag to
fetch and execute a malicious npm package from an attacker-controlled HTTP
server, achieving arbitrary command execution on the Flowise host.
This module creates a malicious npm package tar archive in memory, serves it
via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint
to download and execute the package via npx.
To interact with the obtained shell, use the command: sessions -i <id>
(for example: sessions -i 1).