Find notable cyber news and cases, enriched with sources, timelines, and signals.

Flowise code injection flaw (CVE-2025-59528)

Vulnerability
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2025-59528 is being actively exploited in Flowise, putting exposed servers at risk of remote code execution and full system compromise. The flaw is a maximum-severity code injection issue in the CustomMCP node, where a user-controlled `mcpServerConfig` string is parsed and JavaScript is executed without validation. Flowise addressed the bug in version 3.0.6, while defenders still face 12,000+ exposed instances and exploitation attempts from a single Starlink IP address.

Timeline

  1. 07.04.2026 08:56 2 articles · 1mo ago

    VulnCheck discloses active exploitation of Flowise CVE-2025-59528

    Initial Disclosure

    VulnCheck disclosed active exploitation of Flowise deployments using CVE-2025-59528, a CVSS 10.0 code injection flaw in the CustomMCP node that can execute arbitrary JavaScript and lead to remote code execution, full system compromise, file system access, command execution, and sensitive data exfiltration; the activity has been linked to a single Starlink IP address, and Flowise addressed the issue in version 3.0.6.

    Show sources