THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xc48-889x-5qmw (high) — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

[GHSA] GHSA-xc48-889x-5qmw (high) — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

medgithub_advisoriesPublished 2026-08-04

GHSA-xc48-889x-5qmw Severity: high CVE: CVE-2026-69263

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

## Summary

The mitigation shipped for CVE-2025-8943 blocks the `-y` and `--yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xc48-889x-5qmw