Vulnerabilities/

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

Severity:
High

Description

The mitigation shipped for CVE-2025-8943 blocks the -y and --yes flags on npx to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies only four variable names by exact string match, and npm reads its configuration directly from npm_config_* environment variables.

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-components
Anything's wrong? Let us know Last updated on August 04, 2026