Attackers Exploit Flowise Injection Vulnerability as 15,000+ Instances Remain Exposed
ID: 96a9e91d-6eee-597b-a6a5-70d4a4af6c71
STIX ID: report--96a9e91d-6eee-597b-a6a5-70d4a4af6c71
Feed Name: GBHackers
Threat Score
**Executive Summary:** Critical code-injection vulnerability CVE-2025-59528 in Flowise's CustomMCP node allows remote attackers to execute arbitrary code (CVSS 10.0); active exploitation has been observed in the wild and up to ~15,000 instances may be exposed, so administrators must upgrade affected instances to Flowise 3.0.6 immediately to mitigate full host compromise and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
