Skip to content

Security: Persistent code execution via Flow Node definitions in database #16

Description

@kennethkcox

Security Advisory: Persistent Code Execution in Flow Studio

Summary

The Flow Studio subsystem stores custom Python node definitions in the database and executes them via exec() when users run flows. While node creation requires admin access, this creates a persistent code execution vector that affects all authenticated users.

Affected Component

  • File: backend/flow_engine.py:84
  • Function: execute_node_isolated()
  • Sink: exec(compiled_code, {}, local_scope) where compiled_code comes from FlowNodeDefinition.code (database)

Technical Details

  1. Admin creates node: POST /api/flows/nodes stores arbitrary Python code in FlowNodeDefinition.code
  2. Code persists: Node definition remains in database until manually deleted
  3. Any user triggers: POST /api/flows/execute runs flows containing the node, executing the stored code
  4. No sandboxing: Code runs with full server privileges, no restrictions on imports or system calls

Impact Scenarios

Scenario Impact
Admin compromise (phishing/session hijack) Attacker plants persistent backdoor surviving account recovery
Malicious admin Insider threat can execute code via any user's flow execution
No audit trail Regular users have no visibility into what code nodes execute

Why This Matters

  • Persistence: Unlike one-shot RCE, this backdoor survives restarts and admin account recovery
  • Cross-user impact: Single admin action affects all authenticated users
  • No sandboxing: Code executes with full server privileges
  • Flow Studio is new: No prior security hardening visible in this subsystem

Comparison to Existing Vulnerabilities

This differs from previously reported lollms vulnerabilities (path traversal in file system, extension install RCE) because:

  • Targets the Flow Studio workflow system (new attack surface)
  • Uses database-stored code execution (not direct endpoint exploitation)
  • Creates persistent backdoor (not one-shot RCE)

Remediation Recommendations

  1. Short-term: Add audit logging for node creation and execution
  2. Medium-term: Run node code in isolated containers (gVisor, Firecracker, or restricted Docker)
  3. Long-term: Replace exec() with predefined node library or secure sandbox (note: RestrictedPython has known escapes via CVE-2023-37271, CVE-2025-22153)

Proof of Concept (Conceptual)

# Admin creates malicious node
POST /api/flows/nodes
{
  "name": "malicious_node",
  "code": "import os; os.system('echo VULNERABLE')",
  "class_name": "CustomNode",
  ...
}

# Any user executes flow with this node
POST /api/flows/execute
{
  "flow_id": "<flow_with_malicious_node>"
}
# Server executes the malicious code

Notes

  • This is reported responsibly to help secure the Flow Studio subsystem before wider adoption
  • No active exploit in the wild (to my knowledge)
  • Happy to discuss remediation options

Environment:

  • Repository: ParisNeo/lollms
  • Revision: HEAD (pulled 2026-05-29)
  • Flow Studio subsystem enabled

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions