← Vulnerability feed

Vulnerability record · CVE-2025-8943 · published 14 August 2025

CVE-2025-8943: Flowise Custom MCPs feature allows unauthenticated OS command execution

Flowiseai · Flowise

Flowise's Custom MCPs feature is meant to run OS commands such as npx to start local MCP servers, but the platform's authentication and authorization model is minimal and lacks role-based access controls. In versions before 3.0.1, a default installation runs without authentication unless explicitly configured, so the command execution path is reachable without credentials. The result is unauthenticated remote code execution on the host running Flowise.

9.8 CVSS 3.1 Critical EPSS 66% · top 0.8% CWE-306 · Missing authentication for critical functionCWE-862 · Missing authorization
9.8CVSS 3.1 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable OS command execution with a CVSS of 9.8 and high EPSS, though no confirmed in-the-wild exploitation is documented.

What it is

Flowise's Custom MCPs feature is meant to run OS commands such as npx to start local MCP servers, but the platform's authentication and authorization model is minimal and lacks role-based access controls. In versions before 3.0.1, a default installation runs without authentication unless explicitly configured, so the command execution path is reachable without credentials. The result is unauthenticated remote code execution on the host running Flowise.

Impact

An attacker gains unsandboxed OS command execution on the Flowise host, leading to full compromise of confidentiality, integrity and availability of that system and anything reachable from it.

Attack surface

Reachable over the network via the Custom MCPs feature; the CVSS vector is AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. The description confirms default pre-3.0.1 installs have no authentication unless configured.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.663 (99.2nd percentile) and the sole reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Flowise to 3.0.1 or later, which removes the unauthenticated default behavior.
  • If upgrade is not immediately possible, enable authentication explicitly and restrict network access to the Flowise instance to trusted hosts only.
  • Disable or remove the Custom MCPs feature where it is not required, since it is designed to execute OS commands.
  • Run Flowise under a low-privilege service account with no access to sensitive files or credentials, and isolate it from internal networks.
  • Monitor for unexpected child processes such as npx or shell commands spawned by the Flowise process.

Detection

  • Alert on Flowise process spawning shells or commands like npx, node, sh or bash, especially outside expected startup windows.
  • Review Flowise access logs for unauthenticated requests to MCP or custom tool endpoints from unexpected source IPs.
  • Baseline and monitor outbound connections from the Flowise host for command-and-control or download activity following MCP requests.
  • Audit Flowise configuration to confirm authentication is enabled and identify instances still running pre-3.0.1 defaults.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8943 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-71338Flowiseai flowise vulnerabilityFlowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outsid…EPSS 1.2%10.0CVE-2025-59528Flowise CustomMCP node code injection enables remote code executionFlowise 3.0.5 passes user-supplied mcpServerConfig input directly into the JavaScript Function() constructor inside convertToValidJSONString, with no…EPSS 86%analysed9.9CVE-2026-40933Flowiseai flowise os command injection vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…EPSS 1.3%9.9CVE-2025-61913Flowiseai flowise path traversal vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…EPSS 13%9.8CVE-2026-52098Flowiseai flowise code injection vulnerabilityAn issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpointEPSS 1.1%9.8CVE-2026-41267Flowiseai flowise insecure direct object reference vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…EPSS 0.48%9.8CVE-2026-41268Flowiseai flowise improper input validation vulnerabilityFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…EPSS 1.2%9.8CVE-2025-58434Flowise forgot-password endpoint leaks reset token, enabling account takeoverFlowise 3.0.5 and earlier returns a valid password reset tempToken and sensitive account details from the forgot-password endpoint without authentica…EPSS 50%analysed

Source: NIST National Vulnerability Database (record CVE-2025-8943), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.