Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2025-71336: Flowise Custom MCP feature allows attackers to execute OS commands
CVE-2025-71336
Summary
Flowise versions 2.2.7-patch.1 and earlier are at risk of attackers executing arbitrary OS commands on the system. This is because the software's security settings are not strong enough, and an attacker can send a specific request to the system. To protect your system, update to version 3.0.6 or later.
Original title
Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands su...
Original description
Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks role-based access control, and the default installation runs without authentication unless FLOWISE_USERNAME and FLOWISE_PASSWORD are set, an attacker can send a crafted JSON payload with the header 'x-request-from: internal' to the /api/v1/node-load-method/customMCP endpoint to execute arbitrary OS commands, resulting in complete compromise of the platform container or server.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-78
OS Command Injection
Published: 25 Jun 2026 · Updated: 23 Jul 2026 · First seen: 25 Jun 2026