Critical Flowise RCE Vulnerability Actively Exploited, Thousands of Systems at Risk
ID: f22aed17-6ea9-5044-b486-eaffa0795632
STIX ID: report--f22aed17-6ea9-5044-b486-eaffa0795632
Feed Name: The Cyber Express
Threat Score
Flowise, an open-source low-code platform for building AI agents, has a critical RCE (CVE-2025-59528) in its CustomMCP node allowing arbitrary JavaScript execution; exploitation has been observed in the wild (detected by VulnCheck’s Canary), patches are available in versions 3.0.6 and 3.1.1, and users are strongly advised to update and remove unnecessary public exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
