people · May 20, 2026
OX Security Audit Reveals Command Execution Flaw in 200000 AI Agent Servers Including Flowise
Share the canonical public link.
VentureBeat reported on May 1, 2026 that OX Security found 200000 vulnerable AI agent servers with command execution flaws. Researchers demonstrated allowlist bypasses on Flowise and Upsonic using npx -c argument injection. The audit produced over 10 CVEs rated high or critical across Flowise, LangFlow, LiteLLM and other platforms.
Below validation threshold — auto-passed without scoring