CVE-2025-59528: critical vulnerability in FlowiseAI Flowise
Flowise has Remote Code Execution vulnerability
Published
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 86%
from disclosure to weapon39 days
Published on NVDSep 22
1st PoC+39d
metasploitSep 13
VulnCheck+195d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
34 public exploit(s)
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
FlowiseAI · Flowisepublic PoCs found — 34
exploitdbwww.exploit-db.com/exploits/52440unverifiedgithubgithub.com/r3nsi15/Flowise-RCE-CVE-2025-59528★ 1githubgithub.com/hackpatato/PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability★ 1githubgithub.com/corey-farley/CVE-2025-59528-Flowise-RCE★ 1githubgithub.com/NymiiTechTips/CVE-2025-59528★ 1githubgithub.com/arensballiu/Flowise-RCE-CVE-2025-59528★ 1githubgithub.com/UsifAraby/CVE-2025-59528-POC★ 1githubgithub.com/vanhari/CVE-2025-59528★ 1githubgithub.com/im-nymii/CVE-2025-59528★ 1githubgithub.com/maradonam18/-CVE-2025-59528-PoC★ 1githubgithub.com/mananispiwpiw/CVE-2025-59528-PoC★ 1githubgithub.com/zimshk/CVE-2025-59528.yaml★ 0githubgithub.com/Moon-Harvest/CVE-2025-59528★ 0githubgithub.com/Amoru-Bek/CVE-2025-59528-Poc★ 0githubgithub.com/Loaxert/CVE-2025-59528-PoC★ 0githubgithub.com/sonnelon/CVE-2025-59528-PoC★ 0vulncheckvulncheck.com/xdb/2c30213b42e0unverifiedvulncheckvulncheck.com/xdb/563083701a16unverifiedvulncheckvulncheck.com/xdb/56a41c9860e4unverifiedvulncheckvulncheck.com/xdb/407a5532a27cunverifiedvulncheckvulncheck.com/xdb/584bb236151eunverifiedvulncheckvulncheck.com/xdb/4ea435a91d53unverifiedvulncheckvulncheck.com/xdb/ff5acae38c2aunverifiedvulncheckvulncheck.com/xdb/808bec20af16unverifiedvulncheckvulncheck.com/xdb/783ea41601faunverifiedvulncheckvulncheck.com/xdb/091dd29241cdunverifiedvulncheckvulncheck.com/xdb/0341f06a864funverifiedvulncheckvulncheck.com/xdb/2a1a4825b0c4unverifiedvulncheckvulncheck.com/xdb/9afe29efcd3bunverifiedvulncheckvulncheck.com/xdb/c66d7108f5e1unverifiedvulncheckvulncheck.com/xdb/3f5adc61e864unverifiedvulncheckvulncheck.com/xdb/263b32bf8c69unverifiedvulncheckvulncheck.com/xdb/677b1c3dfb43unverifiedvulncheckvulncheck.com/xdb/1cbf1594891bunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — FlowiseAI Flowise
In the same product, most dangerous first.
CVE-2025-58434CRITICALFlowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account TakeoverEPSS 49.9%CVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2025-50538HIGHCVE-2025-50538EPSS 14.0%CVE-2024-8182HIGHFlowise Denial of ServiceEPSS 13.9%CVE-2025-61913CRITICALFlowise is vulnerable to arbitrary file read, arbitrary file writeEPSS 13.0%CVE-2025-61687HIGHFlowiseAI/Flosise has File Upload vulnerabilityEPSS 11.1%
References
https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L132https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L220https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L262-L270https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/controllers/nodes/index.ts#L57-L78https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/routes/node-load-methods/index.ts#L5https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/services/nodes/index.ts#L91-L94https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7p