peter bassill · operator
$ cve CVE-2025-8943 JSON

CVE-2025-8943

9.8
CRITICAL · CVSS 3.1 · EPSS 65.8% (pctl 99)

Patch early

EPSS 65.8% — above the 10% action threshold.

Description

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS65.77% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2025-08-14
Last modified2026-06-17

Affected (1)

VendorProduct
flowiseaiflowise

References

→ the Explorer  ·  watch your stack  ·  NVD