Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40933

44
FAUCET Score

OVERVIEW CVE-2026-40933 is a critical remote code execution vulnerability in Flowise, a drag-and-drop UI platform for building customized large language model workflows. The flaw exists in versions prior to 3.1.0 and stems from unsafe serialization of stdio commands in the MCP (Model Context Protocol) adapter. An authenticated attacker can bypass input sanitization checks by adding a malicious MCP stdio server with arbitrary commands, enabling direct command execution on the underlying operating system. SEVERITY The vulnerability carries a CVSS 3.1 score of 9.9 (Critical) with network-based attack vector, low complexity, and low privilege requirements. The attacker needs valid authentication but can achieve high-impact outcomes across the system, including complete confidentiality, integrity, and availability compromise. The vulnerability is particularly dangerous because existing input validation mechanisms, including validateCommandInjection and validateArgsForLocalFileAccess functions, can be circumvented through command argument manipulation such as combining the "npx" command with execution flags like "-c touch /tmp/pwn". EXPLOITATION STATUS There is no evidence of active exploitation in the wild at this time. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on exploitation tracking lists. However, the attack requires only authenticated access and straightforward technical knowledge, making it a moderate concern for organizations running vulnerable Flowise instances. Users should prioritize patching to version 3.1.0 or later to remediate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.1.0CPE matchmatch criteria
cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
13.36%
Probability of exploitation in next 30 days
EPSS Percentile
96.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1336 is in the 95th percentile among its peer group of 1,128 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

npmpatch availablevia ghsa
Product: flowiseFixed in: 3.1.0
npmpatch availablevia ghsa
Product: flowise-componentsFixed in: 3.1.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-c9gw-hvqq-f33rcritical

Flowise: Authenticated RCE Via MCP Adapters

Apr 16, 2026

References

github.com / FlowiseAI/Flowise/security/advisories/GHSA-c9gw-hvqq-f33r
ExploitVendor Advisory
ox.security / blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem
Press/Media CoverageThird Party Advisory
ox.security / blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp
Press/Media CoverageThird Party Advisory