Vulnerabilities & Exploits · Web App Attack

AI Workflow Builder Flaw Enables Full Server Takeover

Flowise's CustomMCP node executes attacker-supplied JavaScript with full Node.js privileges, turning API access into a direct path for OS-level command execution, file system access, and data theft. This breaks the assumption that AI workflow configurations are isolated from the host system. CVE-2025-59528 has been actively exploited for over six months across more than 12,000 internet-exposed Flowise instances, making this a widespread and urgent risk. The vulnerability allows attackers to bypass app-layer containment and compromise the entire server, not just the Flowise application. Patch version 3.0.6 addresses this critical flaw. Immediate remediation is essential to prevent full system compromise and data loss.

3 sources · Apr 7

Community Assessment

Security media reported active CVSS 10.0 exploitation, while threat researchers add a chained PoC: CVE-2025-58434 for unauthenticated takeover, then CVE-2025-59528 for unauthenticated RCE in one automated run.

CVE-2025-59528

NVD KEV

CVSS 10 CRITICAL: flowise is a drag & drop user interface to build a customized large language model flow. EPSS 86% (100th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-01

Every edition of this story: AI Workflow Builder Flaw Enables Full Server Takeover

More from today