CVE-2025-26319Active Exploitation(flowiseai / flowise)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
flowise

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-07: 2Active Exploitation · 2026-04-07: 2Patch / Workaround · 2026-04-07: 2Technical Details · 2026-04-07: 204-07
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Syed Aquib@syedaquib77
    Active Exploitation

    ⚠️ **Vulnerability Alert:** Flowise — Critical RCE & related vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) 📅 **Timeline:** Disclosure: 2025-03-04; Patch: 2025-09-15 🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.224% 🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.302% 🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.082% 🛠️ **Exploit Maturity:** Actively Exploited 📂 **Affected Versions:** Flowise <3.0.6 (CustomMCP), deployments using CustomMCP evaluating untrusted mcpServerConfig, Flowise <3.0.1 (unauthenticated Custom MCPs), Flowise v2.2.6 (/api/v1/attachments) 🔧 **Fixed Versions:** 3.0.6, 3.1.1, 3.0.1 🫨 **Attack Vectors:** - Network-facing CustomMCP node JS evaluation → arbitrary JS execution - Unauthenticated Custom MCPs → unsandboxed OS command execution - Arbitrary file upload via /api/v1/attachments enabling malicious payloads 📝 **Summary:** Critical RCE and related flaws let attackers run arbitrary JavaScript and OS commands via the CustomMCP node and upload malicious payloads via attachments, enabling full host compromise. Multiple CVEs are actively exploited in the wild and an estimated 12k–15k Flowise instances are exposed online. 📈 **Impact Scope:** High — remote code execution, filesystem access, credential theft and full host compromise; multiple CVEs observed exploited in the wild. 🛡️ **Recommended Actions:** - Immediately upgrade to patched releases (>=3.0.6 or 3.1.1; ensure 3.0.1 for auth fixes). - If you cannot upgrade immediately: disable/remove CustomMCP, block MCP config inputs, restrict network exposure (VPN/WAF/firewall), audit logs for IOCs, isolate suspected hosts and rotate credentials. 🪢 **Related Resources:** - https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/ - https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6 🏷 **Tags:** #Cybersecurity #Flowise #RCE

    Post summary

    The text reports that three critical RCE CVEs (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) in Flowise have been actively exploited in the wild, with remedial patches available but many instances still exposed.

    00000126
    276 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    ⚠️ **Vulnerability Alert:** Flowise — Multiple critical RCE and unsafe input handling vulnerabilities (CVE-2025-59528, CVE-2025-8943, CVE-2025-26319) 📅 **Timeline:** Disclosure: 2025-09-22, Patch: 2025-09-23 🆔 **CVE-2025-59528** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 99.22% 🆔 **CVE-2025-8943** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.30% 🆔 **CVE-2025-26319** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.08% 🛠️ **Exploit Maturity:** Actively Exploited 📂 **Affected Versions:** prior to 3.0.6 (3.0.0–3.0.5), prior to 3.0.1, v2.2.6 🔧 **Fixed Versions:** 3.1.1 (recommended), 3.0.6, 3.0.1 🫨 **Attack Vectors:** - Network-facing input evaluation in CustomMCP → arbitrary JavaScript evaluation leading to RCE - CustomMCP executing OS commands via local MCPs (npx) allowing unsandboxed command execution - Arbitrary file upload via /api/v1/attachments allowing file write and potential code execution 📝 **Summary:** Critical flaws in Flowise’s CustomMCP and attachment endpoints enable unauthenticated arbitrary JS evaluation, OS command execution, and file uploads that lead to remote code execution and filesystem access. Exploitation is active in the wild and thousands of instances are internet-exposed, raising urgent risk for LLM workflows. 📈 **Impact Scope:** Flowise is widely used for LLM workflows; VulnCheck observed exploitation of CVE-2025-59528 in the wild and estimates 12,000–15,000 Flowise instances exposed online (unknown fraction vulnerable). Successful exploitation enables remote code execution, command execution, and filesystem access on exposed hosts. 🛡️ **Recommended Actions:** - Immediately upgrade to 3.1.1 (minimum 3.0.6 / 3.0.1 where applicable) - If you cannot patch immediately, remove from public internet or restrict access (IP allowlist, VPN) - Disable or restrict CustomMCP usage; validate/sanitize mcpServerConfig and avoid running Flowise as root - Scan logs/apply vendor IOCs/signatures, rotate credentials, and isolate suspected compromised hosts - Implement authentication/RBAC and enforce least privilege for Flowise services 🪢 **Related Resources:** - https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/ - https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6 🏷 **Tags:** #Cybersecurity #Flowise #RCE

    Post summary

    The post announces that Flowise suffers from multiple critical RCE vulnerabilities that are actively exploited in the wild, provides patch information, and presents detailed technical exploitation scenarios.

    00000149
    276 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise2.2.6--

Explore more