FlowiseGHSA-2vv2-3x8x-4gv7
Flowise OS command remote code execution
Critical9.8CVE-2025-8943 · Published Aug 14, 2025 · updated Aug 18, 2025
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| flowise npm | <= 3.0.5 | No fix yet |
Details and references
More Flowise advisories
All Flowise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 152025 | Flowise has arbitrary file access due to missing chat flow id validation | Critical9.8 | 3.0.6 |
| Sep 152025 | Flowise has an Arbitrary File Read | Critical9.1 | 3.0.6 |
| Sep 152025 | Flowise has Remote Code Execution vulnerability | Critical10.0 | 3.0.6 |
| Sep 152025 | FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability | High7.5 | 3.0.6 |
| Sep 152025 | FlowiseAI Pre-Auth Arbitrary Code Execution | Critical9.1 | 3.0.6 |
| Sep 122025 | Flowise: information disclosure | Critical9.8 | 3.0.6 |