CVE-2025-59528
CVSS 10 CRITICAL: flowise is a drag & drop user interface to build a customized large language model flow. EPSS 86% (100th percentile).
Vulnerabilities & Exploits · Web App Attack
Flowise's CustomMCP node executes attacker-supplied JavaScript with full Node.js privileges, turning API access into a direct path for OS-level command execution, file system access, and data theft. This breaks the assumption that AI workflow configurations are isolated from the host system. CVE-2025-59528 has been actively exploited for over six months across more than 12,000 internet-exposed Flowise instances, making this a widespread and urgent risk. The vulnerability allows attackers to bypass app-layer containment and compromise the entire server, not just the Flowise application. Patch version 3.0.6 addresses this critical flaw. Immediate remediation is essential to prevent full system compromise and data loss.
3 sources · Apr 7
Security media reported active CVSS 10.0 exploitation, while threat researchers add a chained PoC: CVE-2025-58434 for unauthenticated takeover, then CVE-2025-59528 for unauthenticated RCE in one automated run.
CVSS 10 CRITICAL: flowise is a drag & drop user interface to build a customized large language model flow. EPSS 86% (100th percentile).
SecurityWeek
Critical Flowise Vulnerability in Attacker Crosshairs
The improper validation of user-supplied JavaScript code allows attackers to execute arbitrary code and access the file system.
originalBleepingComputer
Max severity Flowise RCE vulnerability now exploited in attacks
Hackers are exploiting a maximum-severity vulnerability, tracked as CVE-2025-59528, in the open-source platform Flowise for building custom LLM apps and agentic systems to execute arbitrary code.
originalThe Hacker News
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
CVE-2025-59528 exploited in Flowise for over six months across 12,000+ exposed instances, enabling full system compromise.
originalPart of the PlainSec briefing for 2026-04-07
Every edition of this story: AI Workflow Builder Flaw Enables Full Server Takeover