PT-2025-33147 · Flowise · Flowise
Assaf Levkovich
·
Published
2025-08-14
·
Updated
2026-04-07
·
CVE-2025-8943
CVSS v2.0
10
Critical
| AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.0.1
Description
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like
npx to spin up local MCP Servers. Flowise’s authentication and authorization model is minimal and lacks role-based access controls (RBAC). The default installation operates without authentication unless explicitly configured. This allows unauthenticated network attackers to execute unsandboxed OS commands via the Custom MCPs feature. The vulnerability allows for Remote Code Execution (RCE).Recommendations
Flowise versions prior to 3.0.1 should be updated to version 3.0.1 or later.
Exploit
Fix
RCE
Missing Authentication
OS Command Injection
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowise