Flowise OS command remote code execution
Critical severity
GitHub Reviewed
Published
Aug 14, 2025
to the GitHub Advisory Database
•
Updated Aug 18, 2025
Description
Published by the National Vulnerability Database
Aug 14, 2025
Published to the GitHub Advisory Database
Aug 14, 2025
Reviewed
Aug 14, 2025
Last updated
Aug 18, 2025
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like
npx
to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.References