Description
Due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.0.13
- Patched version(s): 3.1.0
References
Could your website be exposed too?
SmartScanner can check your website for Flowise: Authenticated RCE Via MCP Adapters and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation - CVE-2026-69264
- Flowise: Code Injection in CSVAgent leads to Authenticated RCE - CVE-2026-41137
- Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) - CVE-2026-69263
- Flowise RCE via SQLite Record Manager Node - CVE-2026-69259
You might also like:
See something that needs correcting? Let us knowUpdated April 16, 2026


