Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Unauthenticated users can trigger package auto-install and achieve remote code execution on default Flowise deployments.

1 CRIT · 8 HIGH · 2 MED · 1 INFO · THREAT RED · 12 items · Generated in 257s
Unauthenticated users can trigger package auto-install and achieve remote code execution on default Flowise deployments.
Scoped reads can leak data across tenant namespaces when labels share prefixes, breaking isolation in affected stores.
An authenticated user can use server-side fetches to access internal services or cloud metadata and exfiltrate sensitive data.
Read-only users can access server-side tool source, exposing sensitive logic and possibly embedded secrets.
Authenticated users can exfiltrate internal data through the Playwright loader via SSRF when that non-default feature is enabled.
Lets a logged-in attacker bypass SSRF checks and fetch internal resources, often returning the response to the attacker.
A malicious message can make a victim browser fetch internal or trusted URLs and expose response data to the page.
Revoked users can bypass server-side checks and consume image-generation capability they were denied.
Mentions MCP supply-chain attacks and a Metabase 0-day, signaling active AI and software ecosystem risk worth tracking.
Blocked-request logs can carry attacker text that an agent may later execute as instructions.
A new restricted cyber-focused model may affect defender and researcher workflows, but the item states no direct vulnerability or exploit.
A widely exploited SQL injection in Metabase can lead to data access or server compromise; active exploitation raises urgency.