THREAT OPS › Threat News › [GHSA] GHSA-xc48-889x-5qmw (high) — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
[GHSA] GHSA-xc48-889x-5qmw (high) — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
GHSA-xc48-889x-5qmw Severity: high CVE: CVE-2026-69263
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
## Summary
The mitigation shipped for CVE-2025-8943 blocks the `-y` and `--yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2025-8943cve
- CVE-2026-69263cve
Original source: https://github.com/advisories/GHSA-xc48-889x-5qmw