CVE-2025-71336: Flowise - Unsandboxed Remote Code Execution via Custom MCP
Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks role-based access control, and the default installation runs without authentication unless FLOWISEUSERNAME and FLOWISEPASSWORD are set, an attacker can send a crafted JSON payload with the header 'x-request-from: internal' to the /api/v1/node-load-method/customMCP endpoint to execute arbitrary OS commands, resulting in complete compromise of the platform container or server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flowiseto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
Flowiseto a version that resolves this vulnerability.Fixed in 2.2.7-patch.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71336?
The severity of CVE-2025-71336 is rated as critical with a score of 9.3.
What types of systems are affected by CVE-2025-71336?
CVE-2025-71336 affects Flowise versions 2.2.7-patch.1 and earlier, specifically versions prior to 3.0.6.
How do I fix CVE-2025-71336?
To fix CVE-2025-71336, upgrade Flowise to version 3.0.6 or later.
What type of vulnerability is CVE-2025-71336?
CVE-2025-71336 is identified as an unsandboxed remote code execution vulnerability due to OS command injection.
What is the impact of CVE-2025-71336 on my system?
CVE-2025-71336 could allow an attacker to execute arbitrary OS commands, leading to potential full compromise of the system.