logo

Attackers exploit critical Flowise flaw CVE-2025-59528 for remote code execution

ID: c7f4770e-2022-5a7c-83d8-41e59258cc36

STIX ID: report--c7f4770e-2022-5a7c-83d8-41e59258cc36

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Attackers are actively exploiting CVE-2025-59528, a critical (CVSS 10) Flowise vulnerability that executes user-supplied JavaScript via the CustomMCP node, enabling full system takeover, command execution, and file access; VulnCheck observed initial exploitation from a Starlink IP and estimates 12,000–15,000 exposed instances, and Flowise patched the issue in version 3.0.6.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.