Vulnerability  ·  2026-04-15

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation (CVE-2025-59528)

VulnerabilityHigh impactCVE-2025-59528
Active exploitation of a maximum-severity (CVSS 10.0) code injection vulnerability in Flowise's CustomMCP node was confirmed in early April 2026 by VulnCheck researchers. Despite being patched in September 2025 (version 3.0.6), 12,000–15,000 instances remain exposed online. The vulnerability allows JavaScript code execution during MCP server configuration parsing without security validation.
Attackers inject malicious code through the CustomMCP node configuration, gaining access to child_process (command execution) and fs (file system) with full Node.js runtime privileges. Flowise instances typically hold API keys for OpenAI, Anthropic, Azure OpenAI, and credentials for databases and internal systems.
Flowise versions prior to 3.0.6. All organisations using Flowise for AI agent workflows with MCP server integrations are at risk.
Upgrade Flowise to version 3.0.6 or later immediately. Audit exposed Flowise instances for compromise indicators. Rotate all API keys and credentials stored in Flowise. Restrict Flowise instances from public internet exposure.
Sources
The Hacker News — Flowise AI Agent Builder Under Active CVSS 10.0 RCE ExploitationSecurity Affairs — Attackers Exploit Critical Flowise FlawCSA Labs — Flowise MCP RCE Exploitation Research NoteSonicWall — FlowiseAI Custom MCP Node RCE
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →