Executive brief
Flowise, an open-source tool for building LLM applications, contains multiple security bypasses in its Model Context Protocol (MCP) feature. These flaws allow an attacker with access to the application to execute arbitrary commands on the underlying server. This could lead to a complete system takeover, unauthorized access to sensitive AI models and data, or disruption of business operations.
Technical details
Flowise is vulnerable to remote code execution (RCE) through three distinct bypasses in the Model Context Protocol (MCP) implementation. First, the 'docker' command blocklist fails to include the 'build' subcommand, allowing attackers to pull and execute malicious Dockerfiles. Second, the 'npx' blocklist only filters the '-y' flag but misses the '--yes' alias, enabling the silent installation and execution of arbitrary npm packages. Third, the 'validateArgsForLocalFileAccess' function uses a flawed regular expression (/^\/[^/]/) that can be bypassed using double slashes (e.g., //etc/passwd), allowing the 'node' command to execute local files. These vulnerabilities require an authenticated account or API access with chatflow update permissions. A patch is available in version 3.1.2.
Affected products
- FlowiseAI flowise <= 3.1.1
- FlowiseAI flowise-components <= 3.1.1
Timeline
- 2026-05-14: advisory: GHSA-m99r-2hxc-cp3q published
- 2026-05-14: patched: Fixed in version 3.1.2