Flowise’s MCP implementation can run ghost commands
A one-click remote code execution vulnerability with a 9.9 CVSS severity rating has been discovered in self-hosted deployments of the open-source Flowise AI platform. Researchers at Obsidian Security …