PT-2025-33147 · Flowise · Flowise

·

CVE-2025-8943

·

Published

2025-08-14

·

Updated

2026-08-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Flowise versions prior to 3.0.1
Description: Flowise, a software platform for building user interfaces over language models (LLM), has a missing authentication check for a critical function. This allows remote, unauthenticated attackers to execute arbitrary operating system commands through the Custom MCPs feature, which is designed to execute OS commands using tools like npx. The inherent authentication and authorization model of Flowise is minimal and lacks role-based access controls (RBAC). Active exploitation of this issue has been detected. The Custom MCPs feature executes OS commands, and the lack of authentication allows attackers to execute unsandboxed OS commands.
Recommendations: Update Flowise to version 3.0.1 or later.

Exploit

Fix

RCE

DoS

Missing Authorization

Missing Authentication

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03234
CVE-2025-8943
GHSA-2VV2-3X8X-4GV7

Affected Products

Flowise