logo

Max severity Flowise RCE vulnerability now exploited in attacks

ID: ce41e787-1aab-59bb-add8-546e8ab3074a

STIX ID: report--ce41e787-1aab-59bb-add8-546e8ab3074a

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Flowise has a critical arbitrary JavaScript injection vulnerability (CVE-2025-59528) in its CustomMCP node that can lead to remote command execution and file system access. VulnCheck detected first-time exploitation in the wild (CVSS-10), activity originated from a single Starlink IP, and between 12,000–15,000 Flowise instances are exposed online; users are urged to upgrade to 3.1.1 (or at least 3.0.6) and remove unnecessary public exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.