Flowise versions 2.2.7-patch.1 and earlier contain a critical unsandboxed remote code execution vulnerability in the Custom MCP feature. (CVE-2025-71336)
Flowise versions 2.2.7-patch.1 and earlier contain a critical unsandboxed remote code execution vulnerability in the Custom MCP feature. This feature executes OS commands to launch local MCP servers. Due to minimal authentication and lack of role-based access control, and default installations running without authentication unless credentials are set, an attacker can send a crafted JSON payload with a specific header to execute arbitrary OS commands. This leads to complete compromise of the platform container or server.
AI Analysis
Technical Summary
Flowise before version 3.0.6 (specifically versions 2.2.7-patch.1 and earlier) is vulnerable to an unsandboxed remote code execution (RCE) vulnerability in its Custom MCP feature. The vulnerability arises because the feature executes OS commands without proper sandboxing. The authentication and authorization model is minimal, lacking role-based access control, and default installations run without authentication unless environment variables FLOWISE_USERNAME and FLOWISE_PASSWORD are set. An attacker can exploit this by sending a crafted JSON payload with the header 'x-request-from: internal' to the /api/v1/node-load-method/customMCP endpoint, resulting in arbitrary OS command execution and full compromise of the platform container or server.
Potential Impact
Successful exploitation allows an unauthenticated attacker to execute arbitrary operating system commands on the affected server or container hosting Flowise. This results in complete compromise of the platform environment, including potential data theft, service disruption, or further lateral movement within the infrastructure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should ensure that FLOWISE_USERNAME and FLOWISE_PASSWORD environment variables are set to enable authentication, thereby preventing unauthenticated access. Additionally, restrict network access to the vulnerable endpoint and monitor for suspicious requests containing the 'x-request-from: internal' header.
Flowise versions 2.2.7-patch.1 and earlier contain a critical unsandboxed remote code execution vulnerability in the Custom MCP feature. (CVE-2025-71336)
Description
Flowise versions 2.2.7-patch.1 and earlier contain a critical unsandboxed remote code execution vulnerability in the Custom MCP feature. This feature executes OS commands to launch local MCP servers. Due to minimal authentication and lack of role-based access control, and default installations running without authentication unless credentials are set, an attacker can send a crafted JSON payload with a specific header to execute arbitrary OS commands. This leads to complete compromise of the platform container or server.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Flowise before version 3.0.6 (specifically versions 2.2.7-patch.1 and earlier) is vulnerable to an unsandboxed remote code execution (RCE) vulnerability in its Custom MCP feature. The vulnerability arises because the feature executes OS commands without proper sandboxing. The authentication and authorization model is minimal, lacking role-based access control, and default installations run without authentication unless environment variables FLOWISE_USERNAME and FLOWISE_PASSWORD are set. An attacker can exploit this by sending a crafted JSON payload with the header 'x-request-from: internal' to the /api/v1/node-load-method/customMCP endpoint, resulting in arbitrary OS command execution and full compromise of the platform container or server.
Potential Impact
Successful exploitation allows an unauthenticated attacker to execute arbitrary operating system commands on the affected server or container hosting Flowise. This results in complete compromise of the platform environment, including potential data theft, service disruption, or further lateral movement within the infrastructure.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should ensure that FLOWISE_USERNAME and FLOWISE_PASSWORD environment variables are set to enable authentication, thereby preventing unauthenticated access. Additionally, restrict network access to the vulnerable endpoint and monitor for suspicious requests containing the 'x-request-from: internal' header.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-q2xp-j85q-883h
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-71336"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 4.0
Threat ID: 6a3ef7d227e9c79719005a5c
Added to database: 06/26/2026, 22:06:10 UTC
Last enriched: 06/26/2026, 22:38:55 UTC
Last updated: 07/31/2026, 19:22:56 UTC
Views: 94
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.