Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rhx-2hcv-q49g

Опубликовано: 23 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.9

Описание

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for example, 'docker build' is not blocked, and 'npx --yes' is not blocked while only '-y' is) and the validateArgsForLocalFileAccess checks, resulting in execution of arbitrary commands on the Flowise host.

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for example, 'docker build' is not blocked, and 'npx --yes' is not blocked while only '-y' is) and the validateArgsForLocalFileAccess checks, resulting in execution of arbitrary commands on the Flowise host.

EPSS

Процентиль: 87%
0.03273
Низкий

8.7 High

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.9
nvd
около 2 месяцев назад

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for example, 'docker build' is not blocked, and 'npx --yes' is not blocked while only '-y' is) and the validateArgsForLocalFileAccess checks, resulting in execution of arbitrary commands on the Flowise host.

EPSS

Процентиль: 87%
0.03273
Низкий

8.7 High

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-78