people · May 18, 2026
OX Security Identifies MCP Supply Chain Flaw in Flowise Allowing RCE
Share the canonical public link.
OX Security researchers identified a critical supply chain vulnerability CVE-2026-40933 in Flowise's MCP adapter. The flaw stems from unsafe serialization of stdio commands, enabling authenticated attackers to execute arbitrary commands via custom MCP stdio servers. Flowise versions up to 3.0.13 were affected, with a patch released in version 3.1.0. OX Security confirmed the bypass of input sanitization best practices in Flowise and Upsonic during their April 2026 audit of 200,000 estimated vulnerable AI agent servers. The research also produced CVEs for similar issues in LiteLLM, LangFlow, and other tools.