Menu

#Flowise

5 posts

Feed·
5 of 5 posts
One-Click RCE Hits Flowise While Gogs Zero-Day Stays Unpatched
🖼️
0

One-Click RCE Hits Flowise While Gogs Zero-Day Stays Unpatched

WebProNews·Tim Toole·4 months ago
#3H3vFdVj
#webpronews#flowise#gogs#self#hosted#code

Public PoC for Flowise CVE-2026-40933 enables one-click RCE via chatflow imports on self-hosted instances. Gogs unauthenticated RCE remains unpatched with Metasploit module available.…

15s
Read More
Flowise MCP RCE: What CVE-2026-40933 Teaches About Agent Security
🖼️
0

Flowise MCP RCE: What CVE-2026-40933 Teaches About Agent Security

DEV Community·tokenmixai·5 months ago
#TL374i3G
#comment#ai#security#flowise#stdio#agent

Flowise CVE-2026-40933 and Upsonic CVE-2026-30625 show why MCP STDIO should be treated as process execution, not harmless plugin config.

15s
Read More