Beveiligingsadvies

CVE-2025-8943

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-08-14 09:54:22
Laatst bijgewerkt 2025-08-18 16:47:58
Toegewezen door JFROG
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.