Security Advisory: Persistent Code Execution in Flow Studio
Summary
The Flow Studio subsystem stores custom Python node definitions in the database and executes them via exec() when users run flows. While node creation requires admin access, this creates a persistent code execution vector that affects all authenticated users.
Affected Component
- File:
backend/flow_engine.py:84
- Function:
execute_node_isolated()
- Sink:
exec(compiled_code, {}, local_scope) where compiled_code comes from FlowNodeDefinition.code (database)
Technical Details
- Admin creates node:
POST /api/flows/nodes stores arbitrary Python code in FlowNodeDefinition.code
- Code persists: Node definition remains in database until manually deleted
- Any user triggers:
POST /api/flows/execute runs flows containing the node, executing the stored code
- No sandboxing: Code runs with full server privileges, no restrictions on imports or system calls
Impact Scenarios
| Scenario |
Impact |
| Admin compromise (phishing/session hijack) |
Attacker plants persistent backdoor surviving account recovery |
| Malicious admin |
Insider threat can execute code via any user's flow execution |
| No audit trail |
Regular users have no visibility into what code nodes execute |
Why This Matters
- Persistence: Unlike one-shot RCE, this backdoor survives restarts and admin account recovery
- Cross-user impact: Single admin action affects all authenticated users
- No sandboxing: Code executes with full server privileges
- Flow Studio is new: No prior security hardening visible in this subsystem
Comparison to Existing Vulnerabilities
This differs from previously reported lollms vulnerabilities (path traversal in file system, extension install RCE) because:
- Targets the Flow Studio workflow system (new attack surface)
- Uses database-stored code execution (not direct endpoint exploitation)
- Creates persistent backdoor (not one-shot RCE)
Remediation Recommendations
- Short-term: Add audit logging for node creation and execution
- Medium-term: Run node code in isolated containers (gVisor, Firecracker, or restricted Docker)
- Long-term: Replace
exec() with predefined node library or secure sandbox (note: RestrictedPython has known escapes via CVE-2023-37271, CVE-2025-22153)
Proof of Concept (Conceptual)
# Admin creates malicious node
POST /api/flows/nodes
{
"name": "malicious_node",
"code": "import os; os.system('echo VULNERABLE')",
"class_name": "CustomNode",
...
}
# Any user executes flow with this node
POST /api/flows/execute
{
"flow_id": "<flow_with_malicious_node>"
}
# Server executes the malicious code
Notes
- This is reported responsibly to help secure the Flow Studio subsystem before wider adoption
- No active exploit in the wild (to my knowledge)
- Happy to discuss remediation options
Environment:
- Repository:
ParisNeo/lollms
- Revision: HEAD (pulled 2026-05-29)
- Flow Studio subsystem enabled
Security Advisory: Persistent Code Execution in Flow Studio
Summary
The Flow Studio subsystem stores custom Python node definitions in the database and executes them via
exec()when users run flows. While node creation requires admin access, this creates a persistent code execution vector that affects all authenticated users.Affected Component
backend/flow_engine.py:84execute_node_isolated()exec(compiled_code, {}, local_scope)wherecompiled_codecomes fromFlowNodeDefinition.code(database)Technical Details
POST /api/flows/nodesstores arbitrary Python code inFlowNodeDefinition.codePOST /api/flows/executeruns flows containing the node, executing the stored codeImpact Scenarios
Why This Matters
Comparison to Existing Vulnerabilities
This differs from previously reported lollms vulnerabilities (path traversal in file system, extension install RCE) because:
Remediation Recommendations
exec()with predefined node library or secure sandbox (note: RestrictedPython has known escapes via CVE-2023-37271, CVE-2025-22153)Proof of Concept (Conceptual)
Notes
Environment:
ParisNeo/lollms