AI Workflow Builder Flaw Enables Full Server Takeover

Flowise's CustomMCP node executes attacker-supplied JavaScript with full Node.js privileges, turning API access into a direct path for OS-level command execution, file system access, and data theft. This breaks the assumption that AI workflow configurations are isolated from the host system. CVE-2025-59528 has been actively exploited for over six months across more than 12,000 internet-exposed Flowise instances, making this a widespread and urgent risk. The vulnerability allows attackers to bypass app-layer containment and compromise the entire server, not just the Flowise application. Patch version 3.0.6 addresses this critical flaw. Immediate remediation is essential to prevent full system compromise and data loss.

Part of the PlainSec briefing for 2026-05-05

Sources