Arc53 A.I CyberSecurity Scoring
Arc53
Company Information
Website:https://arc53.com
Employees number:4
Number of followers:155
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:arc53.com
Arc53 Risk Score (AI oriented)
Between 700 and 749
Arc53IT Services and IT Consulting
Updated:
20/04/2026
20/04/2026
748/1000
Moderate
Ba
Arc53 Global Score (TPRM)
xxxx
Arc53IT Services and IT Consulting
Score locked

Arc53Moderate
Current Score
748Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
749
JULY 2026
749
JUNE 2026
748
MAY 2026
748
APRIL 2026
749
Vulnerability
20 Apr 2026 • Arc53
Anthropic, Flowise, DocsGPT and IBM: Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters
Critical AI Framework Vulnerability Exposes Millions to Remote Code Execution
748
CRITICAL-1
ANTARCFLOIBM1776659058
Critical AI Framework Vulnerability Exposes Millions to Remote Code Execution
Researchers at OX Security have uncovered a severe architectural flaw in the Model Context Protocol (MCP), a communication standard developed by Anthropic and embedded in AI frameworks across Python, TypeScript, Java, and Rust. The vulnerability enables remote code execution (RCE), exposing sensitive data including API keys, internal databases, and chat histories across the AI supply chain.
The flaw affects Flowise, a widely used open-source AI workflow builder, and extends to over 200,000 vulnerable instances, with 150 million downloads and 7,000 publicly accessible servers at risk. During testing, OX Security successfully executed live commands on six production platforms, demonstrating the flaw’s real-world impact.
Key Exploitation Vectors Identified:
- Unauthenticated UI injection in major AI frameworks.
- Hardening bypasses in "protected" environments like Flowise.
- Zero-click prompt injection in AI IDEs (e.g., Windsurf, Cursor).
- Malicious MCP server distribution, with 9 out of 11 registries compromised in testing.
At least ten CVEs have been issued, covering critical vulnerabilities in platforms such as LiteLLM, LangChain, GPT Researcher, DocsGPT, and IBM’s LangFlow.
Despite OX Security’s recommendations for root-level patches, Anthropic declined to implement protocol-wide fixes, describing the behavior as "expected." The company did not oppose the public disclosure of the findings.
The incident underscores systemic risks in AI infrastructure, with the flaw inherited by any developer building on MCP expanding the attack surface across the ecosystem. Security teams are advised to restrict public exposure of AI services, treat MCP inputs as untrusted, and enforce sandboxed environments. Patches for affected platforms are now available.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Arc53 ??
What was Arc53's A.I Rankiteo Cyber Score in July 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in June 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in May 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in April 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in March 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in February 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in January 2026 ??
What was Arc53's A.I Rankiteo Cyber Score in December 2025 ??
What was Arc53's A.I Rankiteo Cyber Score in November 2025 ??
What was Arc53's A.I Rankiteo Cyber Score in October 2025 ??
What was Arc53's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Arc53's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Arc53 ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Arc53's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?