CVE-2025-8943Active Exploitation(flowiseai / flowise)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-20); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-20: 2Mentions · 2026-04-07: 2Mentions · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-04: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-04-07: 2Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-08-04: 1Technical Details · 2026-02-20: 1Technical Details · 2026-04-07: 2Technical Details · 2026-08-04: 102-2004-0708-04
Signal classification4 categories
Active Exploitation
240.0%
General
120.0%
Exploit
120.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-202
Active Exploitation1General1
2026-04-072
Active Exploitation1Exploit1
2026-08-041
Disclosure1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Flowise Unauthenticated OS Command Execution via Custom MCPs (CVE-2025-8943) Flowise's Custom MCPs feature is built to run OS commands (e.g. npx to launch local MCP servers). Because Flowise has a minimal auth model with no RBAC, and before 3.0.1 the default install runs with no authentication at all, an unauthenticated network attacker can execute unsandboxed OS commands on the host - full remote code execution. Flowise is one of the most widely self-hosted AI-agent tools and is often exposed to the internet unconfigured, making this a straightforward RCE target. A public exploit exists. CVSS 9.8. 👉Upgrade Flowise to 3.0.1 or later, enable authentication, and keep it off untrusted networks. Assume compromise if you ran an exposed pre-3.0.1 instance.

    Post summary

    The tweet announces CVE-2025-8943, describing a critical unauthenticated OS command execution flaw in Flowise prior to version 3.0.1, links it to a public exploit, and urges users to upgrade and enable authentication, highlighting its high severity.

    10010177
    281 followersView on X
  • XavSecOps@XavSecOps
    Active Exploitation

    🚨 Active exploitation detected 📦 Product: flowise 🆔 Vuln: CVE-2025-8943 A missing authentication vulnerability in the Custom MCPs feature allows unauthenticated network attackers to execute arbitrary OS commands. ⚠️ Mitigation: Apply security patches immediately. 📈 Score: 9.8 🔗 Source in the first comment 👇

    Post summary

    The message reports that CVE‑2025‑8943 is being actively exploited with a missing authentication flaw that allows remote OS command execution, and it urges users to apply patches immediately.

    1000052
    493 followersView on X
  • Syed Aquib@syedaquib77
    Exploit

    ⚠️ **Vulnerability Alert:** Flowise — Critical RCE & related vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) 📅 **Timeline:** Disclosure: 2025-03-04; Patch: 2025-09-15 🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.224% 🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.302% 🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.082% 🛠️ **Exploit Maturity:** Actively Exploited 📂 **Affected Versions:** Flowise <3.0.6 (CustomMCP), deployments using CustomMCP evaluating untrusted mcpServerConfig, Flowise <3.0.1 (unauthenticated Custom MCPs), Flowise v2.2.6 (/api/v1/attachments) 🔧 **Fixed Versions:** 3.0.6, 3.1.1, 3.0.1 🫨 **Attack Vectors:** - Network-facing CustomMCP node JS evaluation → arbitrary JS execution - Unauthenticated Custom MCPs → unsandboxed OS command execution - Arbitrary file upload via /api/v1/attachments enabling malicious payloads 📝 **Summary:** Critical RCE and related flaws let attackers run arbitrary JavaScript and OS commands via the CustomMCP node and upload malicious payloads via attachments, enabling full host compromise. Multiple CVEs are actively exploited in the wild and an estimated 12k–15k Flowise instances are exposed online. 📈 **Impact Scope:** High — remote code execution, filesystem access, credential theft and full host compromise; multiple CVEs observed exploited in the wild. 🛡️ **Recommended Actions:** - Immediately upgrade to patched releases (>=3.0.6 or 3.1.1; ensure 3.0.1 for auth fixes). - If you cannot upgrade immediately: disable/remove CustomMCP, block MCP config inputs, restrict network exposure (VPN/WAF/firewall), audit logs for IOCs, isolate suspected hosts and rotate credentials. 🪢 **Related Resources:** - https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/ - https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6 🏷 **Tags:** #Cybersecurity #Flowise #RCE

    Post summary

    Flowise’s multiple CVEs (CVE‑2025‑59528, CVE‑2025‑8943, CVE‑2025‑26319) allow remote code and command execution, are actively exploited in the wild, and patches are available for removal.

    00000126
    276 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    ⚠️ **Vulnerability Alert:** Flowise — Multiple critical RCE and unsafe input handling vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) 📅 **Timeline:** Disclosure: 2025-09-22, Patch: 2025-09-23 🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.22% 🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.30% 🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.08% 🛠️ **Exploit Maturity:** Actively Exploited 📂 **Affected Versions:** prior to 3.0.6 (3.0.0–3.0.5), prior to 3.0.1, v2.2.6 🔧 **Fixed Versions:** 3.1.1 (recommended), 3.0.6, 3.0.1 🫨 **Attack Vectors:** - Network-facing input evaluation in CustomMCP → arbitrary JavaScript evaluation leading to RCE - CustomMCP executing OS commands via local MCPs (npx) allowing unsandboxed command execution - Arbitrary file upload via /api/v1/attachments allowing file write and potential code execution 📝 **Summary:** Critical flaws in Flowise’s CustomMCP and attachment endpoints enable unauthenticated arbitrary JS evaluation, OS command execution, and file uploads that lead to remote code execution and filesystem access. Exploitation is active in the wild and thousands of instances are internet-exposed, raising urgent risk for LLM workflows. 📈 **Impact Scope:** Flowise is widely used for LLM workflows; VulnCheck observed exploitation of CVE-2025-59528 in the wild and estimates 12,000–15,000 Flowise instances exposed online (unknown fraction vulnerable). Successful exploitation enables remote code execution, command execution, and filesystem access on exposed hosts. 🛡️ **Recommended Actions:** - Immediately upgrade to 3.1.1 (minimum 3.0.6 / 3.0.1 where applicable) - If you cannot patch immediately, remove from public internet or restrict access (IP allowlist, VPN) - Disable or restrict CustomMCP usage; validate/sanitize mcpServerConfig and avoid running Flowise as root - Scan logs/apply vendor IOCs/signatures, rotate credentials, and isolate suspected compromised hosts - Implement authentication/RBAC and enforce least privilege for Flowise services 🪢 **Related Resources:** - https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/ - https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6 🏷 **Tags:** #Cybersecurity #Flowise #RCE

    Post summary

    Three critical CVEs in Flowise’s CustomMCP and attachment endpoints are actively exploited, exposing thousands of LLM workflow instances to remote code execution. Immediate patching or isolation, along with access restrictions, is urgently recommended.

    00000149
    276 followersView on X
  • XavSecOps@XavSecOps
    General

    🔗 Link: https://app.crowdsec.net/cti/cve-explorer/CVE-2025-8943

    Post summary

    The text only provides a link to the CVE page, without additional details or claims.

    0000033
    493 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more