Critical severity9.8OSV Advisory· Published Aug 14, 2025· Updated Jun 17, 2026
CVE-2025-8943
CVE-2025-8943
Description
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like npx to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
flowisenpm | <= 3.0.5 | — |
Affected products
3[email protected], [email protected], [email protected], …+ 1 more
- (no CPE)range: [email protected], [email protected], [email protected], …
- cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*range: <3.0.1
Patches
Vulnerability mechanics
References
4- research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-2vv2-3x8x-4gv7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-8943ghsaADVISORY
- research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578ghsaWEB
News mentions
1- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router BackdoorsThe Hacker News · Aug 10, 2026