CVE-2025-59528Active Exploitation(flowiseai / flowise)

CRITICALCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 44 mentions and remains active

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 72 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 92 mentions across 22 observed days

What's happening

  • Active exploitation reported across 72 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 34 signals
  • Technical details provided in 81 signals
  • Disclosure: 7 classified signals
  • Peaked 20d ago at 44 mentions (2026-04-07); latest day: 4
  • 92 total mentions across 22 days

Affected systems

Vendors
Products
flowise

1 version affected across 1 product

Deep dive

Activity timeline92 mentions / 22d
011223344Mentions · 2026-04-06: 2Mentions · 2026-04-07: 44Mentions · 2026-04-08: 14Mentions · 2026-04-09: 1Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 2Mentions · 2026-04-14: 2Mentions · 2026-04-15: 4Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-05-06: 1Mentions · 2026-05-09: 1Mentions · 2026-05-11: 1Mentions · 2026-06-13: 1Mentions · 2026-08-12: 2Mentions · 2026-08-29: 2Mentions · 2026-09-18: 1Mentions · 2026-10-02: 4PoC Mentioned / Linked · 2026-04-07: 5PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-15: 2PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-29: 1PoC Mentioned / Linked · 2026-09-18: 1Exploit Tool / Code · 2026-04-07: 1Exploit Tool / Code · 2026-04-10: 1Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-08-12: 1Exploit Tool / Code · 2026-08-29: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-07: 43Active Exploitation · 2026-04-08: 13Active Exploitation · 2026-04-10: 4Active Exploitation · 2026-04-12: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-15: 3Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-06-13: 1Patch / Workaround · 2026-04-07: 21Patch / Workaround · 2026-04-08: 6Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-07: 43Technical Details · 2026-04-08: 13Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 3Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 2Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 4Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-13: 1Technical Details · 2026-08-29: 1Technical Details · 2026-09-18: 104-0604-0804-1004-1204-1404-1604-2005-0605-1108-1209-1810-02
Signal classification6 categories
Active Exploitation
7180.7%
Disclosure
78.0%
PoC
55.7%
Patch
22.3%
Exploit
22.3%
General
11.1%
Referenced assets67 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-062
Active Exploitation1Disclosure1
2026-04-0744
Active Exploitation43Disclosure1
2026-04-0814
Active Exploitation13General1
2026-04-091
Patch1
2026-04-104
Active Exploitation4
2026-04-111
Disclosure1
2026-04-121
Active Exploitation1
2026-04-132
Active Exploitation1Disclosure1
2026-04-142
Active Exploitation1PoC1
2026-04-154
Active Exploitation2PoC2
2026-04-161
Active Exploitation1
2026-04-171
Disclosure1
2026-04-201
Active Exploitation1
2026-04-211
Patch1
2026-05-061
Active Exploitation1
2026-05-091
PoC1
2026-05-111
Active Exploitation1
2026-06-131
Active Exploitation1
2026-08-122
Disclosure1Exploit1
2026-08-292
Disclosure1Exploit1
2026-09-181
PoC1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 Flowise has a CVSS 10.0 RCE flaw (CVE-2025-59528) now under active attack. A bug in MCP config lets attackers run JavaScript with full system access using just an API token. Over 12,000 exposed instances raise risk. 🔗 Exploitation details → https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html

    Post summary

    Flowise’s CVE‑2025‑59528 is a CVSS 10.0 RCE flaw that is reportedly being actively exploited, with exploitation details posted online.

    64051021822.1K
    1.6M followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2025-58434 and CVE-2025-59528: Flowise Dual CVE PoC GitHub: https://github.com/kartik2005221/CVE-2025-58434-AND-59528-POC The two vulnerabilities chain naturally: CVE-2025-58434 provides unauthenticated account takeover, which satisfies the authentication requirement for CVE-2025-59528, achieving unauthenticated RCE in a single automated run.

    Post summary

    The post announces a combined PoC for CVE-2025-58434 and CVE-2025-59528, detailing how the two flaws enable unauthenticated account takeover leading to RCE, and links to a GitHub repository containing the exploit code.

    3170834113.6K
    221.0K followersView on X
  • Hunter@HunterMapping
    Active Exploitation

    🚨Alert🚨 CVE-2025-59528 (CVSS 10.0) :RCE in FlowiseAI/Flowise. 🔥PoC:https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7p 📊 34K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Flowise%22 👇Query HUNTER : http://product.name="Flowise" 📰Refer:https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html https://www.bleepingcomputer.com/news/security/max-severity-flowise-rce-vulnerability-now-exploited-in-attacks/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    CVE-2025-59528 is a high‑severity RCE in FlowiseAI that currently has a proof of concept available and is being actively exploited, as confirmed by multiple security reports.

    28029103.0K
    25.9K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    New VulnCheck KEV: Yesterday, VulnCheck Canaries detected first-time exploitation of CVE-2025-59528, a JavaScript code injection vulnerability in AI development platform Flowise, from a single Starlink IP. 📈12K - 15K instances online. More KEV: https://www.vulncheck.com/kev https://t.co/I2ayWKeEiU

    Post summary

    VulnCheck detected first‑time exploitation of CVE‑2025‑59528, a JavaScript code‑injection flaw on Flowise, confirmed by a single Starlink IP, with an estimated 12k‑15k affected instances online.

    0601692.4K
    3.6K followersView on X
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily #Digest 🚨 Top Exploits: CVE-2025-59528 (CVSS: 10) flowiseai CVE-2026-102427 (CVSS: 10) https://ordasoft.com CVE-2026-76570 (CVSS: 10) https://joomcode.com CVE-2026-85706 (CVSS: 10) gitlab CVE-2020-24186 (CVSS: 10) ..🧵👇

    11041298
    371 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-59528 - critical 🚨 Flowise - Remote Code Execution > Flowise 3.0.5 contains a remote code execution vulnerability caused by unsafe evaluat... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-59528 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a critical remote code execution vulnerability in Flowise 3.0.5, without providing a PoC, exploit code, patch, or evidence of active exploitation.

    01041428
    960 followersView on X
  • ExploitGrid@exploitgrid

    CVE-2025-59528: Flowise RCE CVSS 10.0 | Public exploit EPSS: 86.22% | Composite: 82.3 High The flaw affects Flowise 3.0.5 and involves the CustomMCP node executing attacker-controlled JavaScript. 22 exploits tracked by ExploitGrid. https://exploitgrid.net/vulnerabilities/CVE-2025-59528

    01031313
    371 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    【また君か】AIプラットフォームFlowiseの脆弱性CVE-2025-59528が悪用されている。VulnCheck社報告。脆弱性は2025年9月に修正済みで、CVSSスコア10の遠隔コード実行。外部MCPサーバに接続するCustomMCPノードで、応答を検証せずJavaScriptとして実行していたのが悪い。 https://securityaffairs.com/190471/security/attackers-exploit-critical-flowise-flaw-cve-2025-59528-for-remote-code-execution.html

    Post summary

    Flowise’s CVE‑2025‑59528, rated CVSS 10 for remote code execution, is currently being exploited in the wild and was patched as of September 2025.

    010221.1K
    7.6K followersView on X
  • Daeras@0xDaeras
    PoC

    Hi 👋 Recently published two CVE PoCs on GitHub: - CVE-2024-51482 → ZoneMinder auth time-based blind SQL injection - CVE-2025-58434 + CVE-2025-59528 → FlowiseAI ATO + RCE chain Available here: https://github.com/0xDaeras ⚠️ For educational and authorized security research only.

    Post summary

    Three CVEs are linked to newly released GitHub proofs of concept, detailing SQLi and RCE chain weaknesses, but no exploits, active usage, or patches are discussed.

    000301.1K
    57 followersView on X
  • Jarsy@JarsyInc
    Active Exploitation

    ⚡️Security Brief⚡️ A maximum-severity remote code execution vulnerability was discovered in Flowise, an open-source AI platform. The flaw is identified as CVE-2025-59528 and is currently being actively exploited by threat actors. Attack vector: The vulnerability stems from unsanitized input handling in the platform, enabling attackers to execute arbitrary code remotely on affected systems. Active exploitation indicates immediate risk to deployed instances. Remediation urgency: Organizations running Flowise should prioritize patching or isolating affected instances given the maximum severity rating and ongoing threat actor activity targeting this vulnerability. @Flowise Source: Trend Micro

    Post summary

    A maximum‑severity RCE vulnerability (CVE‑2025‑59528) in Flowise is actively exploited, and organizations are urged to patch or isolate affected systems.

    00021823
    10.3K followersView on X
  • VulnCheck@VulnCheckAI
    Active Exploitation

    VulnCheck’s Canary Intelligence has detected active exploitation of CVE-2025-59528 in Flowise. More than 12,000 instances are exposed to the internet, increasing potential targets. Get the full story and insights from VulnCheck’s VP of Security Research: https://www.securityweek.com/critical-flowise-vulnerability-in-attacker-crosshairs/

    Post summary

    VulnCheck’s Canary Intelligence reports that CVE-2025-59528 is currently being exploited against over 12,000 Flowise instances, indicating active real‑world abuse even though no specific exploit code or patch details are supplied.

    00030276
    767 followersView on X
  • Anavem.com@Anavem_
    Active Exploitation

    Attackers are actively exploiting CVE-2025-59528, a maximum-severity remote code execution vulnerability in Flowise LLM platform. https://www.anavem.com/en/news/cybersecurity/cve-2025-59528-hackers-exploit-critical-flowise-rce-flaw

    Post summary

    The post confirms that attackers are currently exploiting the critical remote code execution flaw CVE-2025-59528 in Flowise LLM.

    01020429
    140 followersView on X
  • Hexon@hexonbot
    Active Exploitation

    Flowise AI platform faces critical CVSS 10.0 RCE vulnerability with 12,000+ exposed instances under active attack. Patch now or get compromised. https://www.hexon.bot/blog/flowise-ai-cve-2025-59528-critical-rce-vulnerability-active-exploitation #AISecurity #CVE #InfoSec

    Post summary

    The post claims the Flowise AI platform is suffering a CVSS 10.0 RCE vulnerability that is actively exploited in the wild, with over 12,000 exposed instances, and urges immediate patching.

    20010141
    404 followersView on X
  • XHack@xhackio
    Active Exploitation

    ⚠️ Flowise AI Platform Under Active RCE Attack A critical vulnerability in the Flowise AI agent builder (CVE-2025-59528, CVSS 10.0) is being actively exploited in the wild. This open-source platform, used to build AI workflows, has over 12,000 exposed instances. The flaw allows unauthenticated remote code execution, giving attackers full control. This is a textbook supply chain risk. Developers integrate these tools into their AI pipelines, often without proper network segmentation or vulnerability management. The attack surface expands rapidly with each new AI component. The lesson here isn't just about patching; it's about applying zero-trust principles to your development and AI tooling. Treat every new library or platform as a potential entry point. 🔍 Key takeaway: AI infrastructure security is now a core part of application security. Isolate your AI development environments, enforce strict access controls, and implement continuous monitoring for anomalous activity in these systems. How is your organization managing the security of AI development tools? Read the full analysis: https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html #cybersecurity #threatintel #infosec

    Post summary

    CVE‑2025‑59528 in Flowise AI is actively exploited in the wild, delivering unauthenticated remote code execution across thousands of exposed instances. No PoC, patch, or exploit code is provided, but the vulnerability’s high severity is highlighted.

    11010182
    24 followersView on X
  • Zion Skank@selfradiance11
    Active Exploitation

    CVE-2025-59528 - CVSS 10.0 in Flowise's CustomMCP node. Unsanitized JS passed to Function() in the MCP server config path. Full RCE. Filesystem access, command execution, credential exfiltration. Active exploitation confirmed April 7. This is the third Flowise RCE exploited in the wild.

    Post summary

    The post confirms active exploitation of CVE‑2025‑59528 with RCE capabilities and detailed technical impact, but provides no PoC, exploit code, or patch information.

    10010300
    165 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Critical Flowise RCE (CVE-2025-59528) actively exploited via CustomMCP; Docker Engine (CVE-2026-34040) & Ninja Forms (CVE-2026-0740) need patches. APT28 hijacks MikroTik/TP-Link DNS to steal Microsoft creds. #FlowiseRCE #APT28DNS #Russia https://ift.tt/SDQ2Mbd

    Post summary

    The post reports active exploitation of Flowise RCE via CustomMCP and highlights the need for patches on Docker Engine and Ninja Forms vulnerabilities, underscoring real-world attacks.

    00020572
    4.4K followersView on X
  • Michael Martino@battista212
    Active Exploitation

    Anthropic Project Glasswing using Claude to secure world's most critical software. Hundreds of organizations compromised daily in Microsoft device code phishing attacks. Attackers exploiting critical Flowise flaw CVE-2025-59528 for remote code execution. Execution becoming easier and more sophisticated.

    Post summary

    The post confirms that CVE-2025-59528 is currently being exploited for remote code execution, with no mention of a PoC, patch, or false positive.

    01010281
    190 followersView on X
  • BotBauR@BotBauR
    Active Exploitation

    ⚠️ ALERTA: La plataforma Flowise AI Agent Builder está siendo explotada activamente (CVE-2025-59528) con un CVSS de 10.0. Miles de instancias en riesgo. https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html #CiberseguridadMX #RCE #CyberSecurity

    Post summary

    The tweet announces that CVE-2025-59528 in Flowise AI Agent Builder is being actively exploited worldwide, with a CVSS score of 10.0 and thousands of instances at risk.

    01010211
    123 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Active Exploitation

    Threat actors are actively exploiting CVE-2025-59528, a maximum-severity (CVSS 10.0) code injection flaw in the popular open-source AI platform Flowise. https://www.redsecuretech.co.uk/blog/post/critical-flowise-rce-vulnerability-actively-exploited/1067 #CyberSecurity #Flowise #RCE #Vulnerability #CVE #OpenSourceSecurity #InfoSec #Exploit #AI https://t.co/3uOenUkbU8

    Post summary

    The post reports that threat actors are actively exploiting CVE-2025-59528, a critical code injection flaw in Flowise, highlighting the vulnerability’s severity and real‑world exploitation.

    01010149
    43 followersView on X
  • Clone Systems@CloneSystemsInc
    Active Exploitation

    Vulnerability Alert — Flowise CVE-2025-59528 (CVSS 10.0) is being actively exploited in Flowise. The flaw allows remote code execution and could lead to full system compromise. Over 12,000 internet-exposed instances may be at risk. Update to Flowise 3.0.6 immediately. https://t.co/IDaTmhCPcD

    Post summary

    CVE-2025-59528 is a critical remote code execution flaw in Flowise that is reportedly being actively exploited, potentially compromising over 12,000 exposed instances; users must upgrade to Flowise 3.0.6 immediately.

    00020231
    243 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise3.0.5--

Explore more