Vulnerability  ·  2026-04-16

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation — 12,000+ Instances Exposed

VulnerabilityHigh impactCVE-2025-59528
A code injection vulnerability in Flowise's CustomMCP Node allows remote attackers to execute arbitrary code without authentication. The CustomMCP node parses user-provided mcpServerConfig strings without security validation, enabling access to dangerous Node.js modules including child_process (command execution) and fs (file system access) with full runtime privileges. First confirmed in-the-wild exploitation was detected from a Starlink IP in early April 2026; between 12,000–15,000 unpatched instances remain reachable on the internet. Critically, Flowise instances typically hold API keys for OpenAI, Anthropic, Azure OpenAI, and other LLM providers — successful exploitation grants access to all downstream AI services.
Unauthenticated remote attacker sends a crafted HTTP request to the CustomMCP node endpoint with a malicious mcpServerConfig payload. No credentials or prior access required. Exploitation gives full system command execution and access to all secrets stored in the Flowise instance.
Flowise versions prior to 3.1.1. Any deployment of Flowise that exposes the CustomMCP node to untrusted input.
Upgrade to Flowise version 3.1.1 immediately. Audit exposed instances for indicators of compromise (unusual outbound connections, unexpected API calls to LLM providers). Rotate all API keys stored in compromised or potentially-compromised Flowise instances. Do not expose Flowise admin interfaces to the public internet without authentication controls.
Sources
The Hacker News — Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances ExposedNVD — CVE-2025-59528 DetailSonicWall Blog — FlowiseAI Flowise RCE via CustomMCP NodeSecurity Affairs — Attackers exploit critical Flowise flaw CVE-2025-59528
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →