Impact
Flowise before 3.1.4 contains a vulnerability in the Custom MCP node that allows an attacker who is authenticated to the Flowise system to execute arbitrary code on the server. By supplying specially crafted npx package names in the mcpServerConfig parameter, the attacker can trigger npx to download and run attacker‑controlled npm packages, resulting in full code execution on the Flowise host.
Affected Systems
The affected product is Flowise by FlowiseAI, with all releases prior to version 3.1.4 vulnerable. Any deployment of Flowise that includes the Custom MCP node and has users with authentication privileges can be impacted.
Risk and Exploitability
The CVSS score of 9 indicates a critical severity level. The EPSS score is < 1%, but the lack of a KEV listing suggests no widely known exploitation at this time. However, because the flaw requires authentication, it is likely to be targeted by internal attackers or compromised credentials. If successfully exploited, an attacker can execute arbitrary code, giving full control over the Flowise server and any connected resources.
OpenCVE Enrichment