logo

Critical Flowise RCE Vulnerability Actively Exploited, Thousands of Systems at Risk

ID: f22aed17-6ea9-5044-b486-eaffa0795632

STIX ID: report--f22aed17-6ea9-5044-b486-eaffa0795632

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Flowise, an open-source low-code platform for building AI agents, has a critical RCE (CVE-2025-59528) in its CustomMCP node allowing arbitrary JavaScript execution; exploitation has been observed in the wild (detected by VulnCheck’s Canary), patches are available in versions 3.0.6 and 3.1.1, and users are strongly advised to update and remove unnecessary public exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.