Vulnerabilities/

Flowise has an MCP Security Bypass that Enables RCE

Severity:
High

Description

There are three bypass methods for the security limitations of the Flowise MCP feature, and attackers can execute arbitrary commands by combining these three methods

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-components
Anything's wrong? Let us know Last updated on May 15, 2026