Flowise MCP Server Remote Code Execution

cve CVE-2026-56274 1 source, 1 claim · Watch

Metasploit exploit modules writes:
Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution through the Custom MCP (Model Context Protocol) node configuration. The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint, which accepts arbitrary command and argument configurations for MCP server initialization. An authenticated attacker can abuse the npx --yes flag to fetch and execute a malicious npm package from an attacker-controlled HTTP server, achieving arbitrary command execution on the Flowise host. This modu… the claim

What each source says

PropertySourceSaidMeans here
Platform
platform
Metasploit exploit modulesUnix
receipt
Source
Metasploit exploit modules
Its words
Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 12:03 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "cn-panda",
    "ABDUL JAFAROV <https://github.com/jafarov007>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n          through the Custom MCP (Model Context Protocol) node configuration.\n\n          The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n          which accepts arbitrary command and argument configurations for MCP server\n          initialization. An authenticated attacker can abuse the npx --yes flag to\n          fetch and execute a malicious npm package from an attacker-controlled HTTP\n          server, achieving arbitrary command execution on the Flowise host.\n\n          This module creates a malicious npm package tar archive in memory, serves it\n          via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n          to download and execute the package via npx.\n\n          To interact with the obtained shell, use the command: sessions -i <id>\n          (for example: sessions -i 1).",
  "disclosure_date": "2026-06-23",
  "fullname": "exploit/multi/http/flowise_mcp_rce",
  "is_install_path": true,
  "mod_time": "2026-08-20 18:02:33 +0000",
  "name": "Flowise MCP Server Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/flowise_mcp_rce",
  "references": [
    "CVE-2026-56274",
    "CWE-78",
    "GHSA-GHSA-m99r-2hxc-cp3q"
  ],
  "rport": 3000,
  "session_types": false,
  "targets": [
    "Unix Command"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 12:03 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "cn-panda",
    "ABDUL JAFAROV <https://github.com/jafarov007>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "Flowise versions from 2.2.7 prior to 3.1.2 are vulnerable to remote code execution\n          through the Custom MCP (Model Context Protocol) node configuration.\n\n          The vulnerability exists in the /api/v1/node-load-method/customMCP endpoint,\n          which accepts arbitrary command and argument configurations for MCP server\n          initialization. An authenticated attacker can abuse the npx --yes flag to\n          fetch and execute a malicious npm package from an attacker-controlled HTTP\n          server, achieving arbitrary command execution on the Flowise host.\n\n          This module creates a malicious npm package tar archive in memory, serves it\n          via Metasploit's built-in HTTP server, then triggers the vulnerable endpoint\n          to download and execute the package via npx.\n\n          To interact with the obtained shell, use the command: sessions -i <id>\n          (for example: sessions -i 1).",
  "disclosure_date": "2026-06-23",
  "fullname": "exploit/multi/http/flowise_mcp_rce",
  "is_install_path": true,
  "mod_time": "2026-08-20 18:02:33 +0000",
  "name": "Flowise MCP Server Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/flowise_mcp_rce.rb",
  "platform": "Unix",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/flowise_mcp_rce",
  "references": [
    "CVE-2026-56274",
    "CWE-78",
    "GHSA-GHSA-m99r-2hxc-cp3q"
  ],
  "rport": 3000,
  "session_types": false,
  "targets": [
    "Unix Command"
  ],
  "type": "exploit"
}
—

exploit

Flowise MCP Server Remote Code Execution
zetlyn/cve-metasploit · 2026-06-23
platform Unix rank 600 source