Security Advisory

CVE-2025-8943

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-14 09:54:22
Last updated 2025-08-18 16:47:58
Assigner JFROG
State PUBLISHED

Description

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowises inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.