Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 npm

Flowise OS command remote code execution

GHSA-2vv2-3x8x-4gv7 · CVE-2025-8943

Published · Modified

Description

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like npx to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.

Ready to move

Start Securing

Free, no credit card | First findings in minutes