logo

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

ID: e667f84f-769f-504d-92ab-8e11f09e79cc

STIX ID: report--e667f84f-769f-504d-92ab-8e11f09e79cc

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Flowise, an open-source AI platform, has a maximum-severity code injection vulnerability (CVE-2025-59528, CVSS 10.0) in its CustomMCP node that can execute arbitrary JavaScript with full Node.js privileges leading to remote code execution, file system access, command execution, and data exfiltration; VulnCheck reports active exploitation originating from a Starlink IP and notes 12,000+ internet-facing instances, while Flowise issued a fix in npm package version 3.0.6.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.