Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a critical vulnerability in Flowise, a platform for building AI applications. The issue, found in the Custom MCP node, allows authenticated users to execute arbitrary code on the server by manipulating specific parameters related to package execution. At a high level, this could potentially lead to unauthorized control over the server hosting the Flowise application.
- Attackers can run unauthorized code on servers.
- Protects against unauthorized code execution risks.
- Confirm relevance and assess exposure to this risk.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access could exploit this vulnerability by providing specific npm package names within the `mcpServerConfig` parameter in the Custom MCP node. This allows them to execute arbitrary code on the Flowise server through the `npx` command, potentially leading to a compromise of the system.
- Requires authenticated user access.
- Triggers via crafted `mcpServerConfig` parameter.
- Risks arbitrary code execution on server.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow authenticated attackers to execute arbitrary code on the Flowise server by supplying npx package names in the mcpServerConfig parameter, when supported by the advisory.
- Server code execution.
- Supplying malicious npx package names.
- Unauthorized server control.
Operational Fix
Recommended remediation, mitigation, and detection steps
Flowise is a platform for building LLM applications, often deployed as a web service. Owners of applications using Flowise and the infrastructure or platform teams supporting these deployments should investigate this vulnerability. The first step is to locate all Flowise instances, assess their reachability and business criticality, identify the accountable owner for each instance, and then plan remediation based on the identified risk.
- Identify Flowise application owners and infrastructure teams.
- Verify Flowise instance reachability and business criticality.
- Plan remediation actions based on risk assessment.