Flowise MCP Server Remote Code Execution
cve CVE-2026-56274 1 source, 1 claim · Watch
Metasploit exploit modules writes:
Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution through the Custom MCP (Model Context Protocol) node configuration. The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint, which accepts arbitrary command and argument configurations for MCP server initialization. An authenticated attacker can abuse the npx --yes flag to fetch and execute a malicious npm package from an attacker-controlled HTTP server, achieving arbitrary command execution on the Flowise host. This modu… the claim
Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution through the Custom MCP (Model Context Protocol) node configuration. The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint, which accepts arbitrary command and argument configurations for MCP server initialization. An authenticated attacker can abuse the npx --yes flag to fetch and execute a malicious npm package from an attacker-controlled HTTP server, achieving arbitrary command execution on the Flowise host. This modu… the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Platform platform | Metasploit exploit modules | Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"cn-panda",
"ABDUL JAFAROV <https://github.com/jafarov007>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n through the Custom MCP (Model Context Protocol) node configuration.\n\n The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n which accepts arbitrary command and argument configurations for MCP server\n initialization. An authenticated attacker can abuse the npx --yes flag to\n fetch and execute a malicious npm package from an attacker-controlled HTTP\n server, achieving arbitrary command execution on the Flowise host.\n\n This module creates a malicious npm package tar archive in memory, serves it\n via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n to download and execute the package via npx.\n\n To interact with the obtained shell, use the command: sessions -i <id>\n (for example: sessions -i 1).",
"disclosure_date": "2026-06-23",
"fullname": "exploit/multi/http/flowise_mcp_rce",
"is_install_path": true,
"mod_time": "2026-08-20 18:02:33 +0000",
"name": "Flowise MCP Server Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/flowise_mcp_rce",
"references": [
"CVE-2026-56274",
"CWE-78",
"GHSA-GHSA-m99r-2hxc-cp3q"
],
"rport": 3000,
"session_types": false,
"targets": [
"Unix Command"
],
"type": "exploit"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"cn-panda",
"ABDUL JAFAROV <https://github.com/jafarov007>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n through the Custom MCP (Model Context Protocol) node configuration.\n\n The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n which accepts arbitrary command and argument configurations for MCP server\n initialization. An authenticated attacker can abuse the npx --yes flag to\n fetch and execute a malicious npm package from an attacker-controlled HTTP\n server, achieving arbitrary command execution on the Flowise host.\n\n This module creates a malicious npm package tar archive in memory, serves it\n via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n to download and execute the package via npx.\n\n To interact with the obtained shell, use the command: sessions -i <id>\n (for example: sessions -i 1).",
"disclosure_date": "2026-06-23",
"fullname": "exploit/multi/http/flowise_mcp_rce",
"is_install_path": true,
"mod_time": "2026-08-20 18:02:33 +0000",
"name": "Flowise MCP Server Remote Code Execution",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/flowise_mcp_rce",
"references": [
"CVE-2026-56274",
"CWE-78",
"GHSA-GHSA-m99r-2hxc-cp3q"
],
"rport": 3000,
"session_types": false,
"targets": [
"Unix Command"
],
"type": "exploit"
} | — |
exploit
| Flowise MCP Server Remote Code Execution zetlyn/cve-metasploit · 2026-06-23 | platform Unix rank 600 | source |