Vulnerabilities · 160 days ago

AI Workflow Builder Flaw Enables Full Server Takeover

Flowise's CustomMCP node executes attacker-supplied JavaScript with full Node.js privileges, turning API access into a direct path for OS-level command execution, file system access, and data theft. This breaks the assumption that AI workflow configurations are isolated from the host system. CVE-2025-59528 has been actively exploited for over six months across more than 12,000 internet-exposed Flowise instances, making this a widespread and urgent risk. The vulnerability allows attackers to bypass app-layer containment and compromise the entire server, not just the Flowise application. Patch version 3.0.6 addresses this critical flaw. Immediate remediation is essential to prevent full system compromise and data loss.

CVE-2025-59528

NVD KEV

CVSS 10 CRITICAL: flowise is a drag & drop user interface to build a customized large language model flow. EPSS 86% (100th percentile).

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-05

Editions

Related stories