Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch flowiseai flowise systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.
🚨Critical - Flowise Unauthenticated OS Command Execution via Custom MCPs (CVE-2025-8943)
Flowise's Custom MCPs feature is built to run OS commands (e.g. npx to launch local MCP servers). Because Flowise has a minimal auth model with no RBAC, and before 3.0.1 the default install runs with no authentication at all, an unauthenticated network attacker can execute unsandboxed OS commands on the host - full remote code execution.
Flowise is one of the most widely self-hosted AI-agent tools and is often exposed to the internet unconfigured, making this a straightforward RCE target. A public exploit exists. CVSS 9.8.
👉Upgrade Flowise to 3.0.1 or later, enable authentication, and keep it off untrusted networks. Assume compromise if you ran an exposed pre-3.0.1 instance.
Post summary
The tweet announces CVE-2025-8943, describing a critical unauthenticated OS command execution flaw in Flowise prior to version 3.0.1, links it to a public exploit, and urges users to upgrade and enable authentication, highlighting its high severity.
🚨 Active exploitation detected
📦 Product: flowise
🆔 Vuln: CVE-2025-8943
A missing authentication vulnerability in the Custom MCPs feature allows unauthenticated network attackers to execute arbitrary OS commands.
⚠️ Mitigation: Apply security patches immediately.
📈 Score: 9.8
🔗 Source in the first comment 👇
Post summary
The message reports that CVE‑2025‑8943 is being actively exploited with a missing authentication flaw that allows remote OS command execution, and it urges users to apply patches immediately.
⚠️ **Vulnerability Alert:** Flowise — Critical RCE & related vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319)
📅 **Timeline:** Disclosure: 2025-03-04; Patch: 2025-09-15
🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.224%
🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.302%
🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.082%
🛠️ **Exploit Maturity:** Actively Exploited
📂 **Affected Versions:** Flowise <3.0.6 (CustomMCP), deployments using CustomMCP evaluating untrusted mcpServerConfig, Flowise <3.0.1 (unauthenticated Custom MCPs), Flowise v2.2.6 (/api/v1/attachments)
🔧 **Fixed Versions:** 3.0.6, 3.1.1, 3.0.1
🫨 **Attack Vectors:**
- Network-facing CustomMCP node JS evaluation → arbitrary JS execution
- Unauthenticated Custom MCPs → unsandboxed OS command execution
- Arbitrary file upload via /api/v1/attachments enabling malicious payloads
📝 **Summary:**
Critical RCE and related flaws let attackers run arbitrary JavaScript and OS commands via the CustomMCP node and upload malicious payloads via attachments, enabling full host compromise. Multiple CVEs are actively exploited in the wild and an estimated 12k–15k Flowise instances are exposed online.
📈 **Impact Scope:** High — remote code execution, filesystem access, credential theft and full host compromise; multiple CVEs observed exploited in the wild.
🛡️ **Recommended Actions:**
- Immediately upgrade to patched releases (>=3.0.6 or 3.1.1; ensure 3.0.1 for auth fixes).
- If you cannot upgrade immediately: disable/remove CustomMCP, block MCP config inputs, restrict network exposure (VPN/WAF/firewall), audit logs for IOCs, isolate suspected hosts and rotate credentials.
🪢 **Related Resources:**
- https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/
- https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6
🏷 **Tags:** #Cybersecurity#Flowise#RCE
Post summary
Flowise’s multiple CVEs (CVE‑2025‑59528, CVE‑2025‑8943, CVE‑2025‑26319) allow remote code and command execution, are actively exploited in the wild, and patches are available for removal.
⚠️ **Vulnerability Alert:** Flowise — Multiple critical RCE and unsafe input handling vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319)
📅 **Timeline:** Disclosure: 2025-09-22, Patch: 2025-09-23
🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.22%
🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.30%
🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.08%
🛠️ **Exploit Maturity:** Actively Exploited
📂 **Affected Versions:** prior to 3.0.6 (3.0.0–3.0.5), prior to 3.0.1, v2.2.6
🔧 **Fixed Versions:** 3.1.1 (recommended), 3.0.6, 3.0.1
🫨 **Attack Vectors:**
- Network-facing input evaluation in CustomMCP → arbitrary JavaScript evaluation leading to RCE
- CustomMCP executing OS commands via local MCPs (npx) allowing unsandboxed command execution
- Arbitrary file upload via /api/v1/attachments allowing file write and potential code execution
📝 **Summary:**
Critical flaws in Flowise’s CustomMCP and attachment endpoints enable unauthenticated arbitrary JS evaluation, OS command execution, and file uploads that lead to remote code execution and filesystem access. Exploitation is active in the wild and thousands of instances are internet-exposed, raising urgent risk for LLM workflows.
📈 **Impact Scope:** Flowise is widely used for LLM workflows; VulnCheck observed exploitation of CVE-2025-59528 in the wild and estimates 12,000–15,000 Flowise instances exposed online (unknown fraction vulnerable). Successful exploitation enables remote code execution, command execution, and filesystem access on exposed hosts.
🛡️ **Recommended Actions:**
- Immediately upgrade to 3.1.1 (minimum 3.0.6 / 3.0.1 where applicable)
- If you cannot patch immediately, remove from public internet or restrict access (IP allowlist, VPN)
- Disable or restrict CustomMCP usage; validate/sanitize mcpServerConfig and avoid running Flowise as root
- Scan logs/apply vendor IOCs/signatures, rotate credentials, and isolate suspected compromised hosts
- Implement authentication/RBAC and enforce least privilege for Flowise services
🪢 **Related Resources:**
- https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/
- https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6
🏷 **Tags:** #Cybersecurity#Flowise#RCE
Post summary
Three critical CVEs in Flowise’s CustomMCP and attachment endpoints are actively exploited, exposing thousands of LLM workflow instances to remote code execution. Immediate patching or isolation, along with access restrictions, is urgently recommended.