Flowise: Critical RCE via MCP stdio Implementation CVE-2026-40933
Flowise's implementation of the Model Context Protocol (MCP) via stdio servers contains a critical sandboxing vulnerability (CVE-2026-40933, CVSS 9.9) allowing post-authentication remote code execution. Attackers can trigger execution by importing a malicious chatflow, exploiting improperly validated MCP configurations to execute arbitrary operating system commands. Despite hardening attempts via PRs #5232, #5741, and #5943, researchers from Obsidian Security demonstrated that these input validation filters are trivially bypassable. Successful exploitation grants the attacker the privileges of the Flowise process, facilitating lateral movement to connected cloud environments, databases, and SaaS applications through exposed API keys and credentials.