
⚠️ **Vulnerability Alert:** Flowise — Critical RCE & related vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) 📅 **Timeline:** Disclosure: 2025-03-04; Patch: 2025-09-15 🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.224% 🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.302% 🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.082% 🛠️ **Exploit Maturity:** Actively Exploited 📂 **Affected Versions:** Flowise <3.0.6 (CustomMCP), deployments using CustomMCP evaluating untrusted mcpServerConfig, Flowise <3.0.1 (unauthenticated Custom MCPs), Flowise v2.2.6 (/api/v1/attachments) 🔧 **Fixed Versions:** 3.0.6, 3.1.1, 3.0.1 🫨 **Attack Vectors:** - Network-facing CustomMCP node JS evaluation → arbitrary JS execution - Unauthenticated Custom MCPs → unsandboxed OS command execution - Arbitrary file upload via /api/v1/attachments enabling malicious payloads 📝 **Summary:** Critical RCE and related flaws let attackers run arbitrary JavaScript and OS commands via the CustomMCP node and upload malicious payloads via attachments, enabling full host compromise. Multiple CVEs are actively exploited in the wild and an estimated 12k–15k Flowise instances are exposed online. 📈 **Impact Scope:** High — remote code execution, filesystem access, credential theft and full host compromise; multiple CVEs observed exploited in the wild. 🛡️ **Recommended Actions:** - Immediately upgrade to patched releases (>=3.0.6 or 3.1.1; ensure 3.0.1 for auth fixes). - If you cannot upgrade immediately: disable/remove CustomMCP, block MCP config inputs, restrict network exposure (VPN/WAF/firewall), audit logs for IOCs, isolate suspected hosts and rotate credentials. 🪢 **Related Resources:** - https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/ - https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6 🏷 **Tags:** #Cybersecurity #Flowise #RCE
Post summary
The text reports that three critical RCE CVEs (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) in Flowise have been actively exploited in the wild, with remedial patches available but many instances still exposed.
