PT-2025-33147 · Flowise · Flowise

Assaf Levkovich

·

Published

2025-08-14

·

Updated

2026-04-07

·

CVE-2025-8943

CVSS v2.0

10

Critical

AV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.0.1
Description The Custom MCPs feature is designed to execute OS commands, for instance, using tools like npx to spin up local MCP Servers. Flowise’s authentication and authorization model is minimal and lacks role-based access controls (RBAC). The default installation operates without authentication unless explicitly configured. This allows unauthenticated network attackers to execute unsandboxed OS commands via the Custom MCPs feature. The vulnerability allows for Remote Code Execution (RCE).
Recommendations Flowise versions prior to 3.0.1 should be updated to version 3.0.1 or later.

Exploit

Fix

RCE

Missing Authentication

OS Command Injection

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-03234
CVE-2025-8943
GHSA-2VV2-3X8X-4GV7

Affected Products

Flowise