CVE-2025-8943: exploitation status and patch state
CVE-2025-8943 · CVSS 9.8 CRITICAL · EPSS 72%
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default installation operates without authentication unless explicitly configured. This combination allows unauthenticated network attackers to execute unsandboxed OS commands.
Is CVE-2025-8943 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 72%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-8943
PlainSec has not published a story about this CVE.