Executive brief
Flowise, a platform for building AI agents, contains a security flaw that allows unauthorized individuals to run commands on the underlying server. Because the software lacks strict access controls and often ships without a default password, an attacker can gain full control over the system. This could lead to the theft of sensitive AI models, data breaches, or complete service disruption.
Technical details
A remote code execution vulnerability exists in Flowise versions prior to 3.0.1 due to the 'Custom MCPs' feature, which is designed to execute OS commands (e.g., using npx) to initialize local Model Context Protocol servers. The vulnerability stems from a combination of CWE-306 (Missing Authentication) and CWE-78 (OS Command Injection). By default, Flowise installations may operate without authentication, and the platform lacks robust Role-Based Access Control (RBAC). An unauthenticated network attacker can send a crafted JSON payload to the 'node-load-method/customMCP' API endpoint to execute arbitrary, unsandboxed OS commands on the host system. The issue is addressed in version 3.0.1.
Affected products
- FlowiseAI Flowise < 3.0.1
Timeline
- 2025-08-14: disclosed
- 2025-08-14: advisory