The Flowise platform , a popular open-source tool for building AI agents and workflows, is under active attack by cybercriminals exploiting a critical vulnerability with a CVSS score of 10.0 . According to new findings from VulnCheck , more than 12,000 exposed instances of Flowise are vulnerable to attacks via the CVE-2025-59528 vulnerability .
See also: Critical Kubernetes Image Builder vulnerability allows SSH access to VMs

The vulnerability affects the platform's CustomMCP node , which allows users to enter configuration settings for connecting to external MCP (Model Context Protocol) servers. The problem lies in the fact that the node parses the user-provided mcpServerConfig string without any security validation, executing JavaScript code with full Node.js runtime privileges .
As Flowise stated in its official announcement in September 2025, successful exploitation of the vulnerability could provide access to dangerous modules such as child_process for command execution and fs for file system access. This means that an attacker could execute arbitrary JavaScript code on the Flowise server, leading to full system compromise, file system access, command execution, and sensitive data theft.
Active Exploitation of Flowise Vulnerability by Cyberattackers
According to data shared by VulnCheck, the exploit activity for the vulnerability is coming from a single Starlink IP address. CVE-2025-59528 is the third Flowise that is actively exploited in the wild, following CVE-2025-8943 with a CVSS score of 9.8 for remote code execution via operating system commands, and CVE-2025-26319 with a CVSS score of 8.9 for arbitrary file upload.
Caitlin Condon, vice president of security research at VulnCheck, stressed the seriousness of the situation: “This is a critical bug in a popular AI platform used by several large companies. This particular vulnerability has been public for over six months, which means defenders have had time to prioritize and patch the vulnerability.”
The fact that there are more than 12,000 exposed instances with an internet-facing attack surface makes the active scanning and exploitation efforts observed more serious, as it means that attackers have ample targets for opportunistic reconnaissance and exploitation.
See also: F5 BIG-IP APM: Critical RCE vulnerability used in attacks

Technical Details and Impact of CVE-2025-59528
The vulnerability was discovered and reported by Kim SooHyun and fixed in version 3.0.6 of the npm package. The issue arises from the use of the unsafe Function() constructor in JavaScript to parse mcpServerConfig strings, allowing unauthenticated arbitrary code execution with full Node.js.
As Flowise, because only an API token, this poses an extreme security risk to business continuity and customer data. The platform is widely used to create drag-and-drop LLM workflows and AI agents,often deployed in development environments, cloud clusters , and CI/CD pipelines.
Flowise has faced multiple critical vulnerabilities in the last 12 months , forming a “6-vuln cluster” with issues such as missing authentication, arbitrary file upload, IDOR , mass assignment, and SSRF with CVSS scores up to 10.0 . Notable examples include CVE -2025-61913 with a CVSS score of 10.0 for authenticated arbitrary file write and CVE-2026-31829 for SSRF in versions below 3.0.13 .
Protection Recommendations and Immediate Measures
Security experts recommend immediately upgrading to Flowise version 3.0.6 or later to address the critical vulnerabilities. Additionally, organizations should revoke compromised API tokens and credentials, conduct filesystem integrity audits, and implement network monitoring for outbound connections.
See also: Critical vulnerability in Telnetd allows Root RCE via Port 23

SentinelOne recommends using behavioral AI detection to identify RCE patterns , while emphasizing the importance of limiting public exposure and enforcing authentication, input sanitization, and least-privilege Node.js execution. For AI pipelines , it is critical to isolate deployments, rotate keys , and re-examine connected cloud buckets .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
