Flowise has Remote Code Execution vulnerability
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 90%
from disclosure to weapon39 days
Published on NVDSep 22
1st PoC+39d
metasploitSep 13
VulnCheck+195d
exploitation probability
90%top 1% of all CVEs
observed exploitation
yesVulnCheck
26 public exploit(s)
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
FlowiseAI · Flowisepublic PoCs found — 26
exploitdbwww.exploit-db.com/exploits/52440unverifiedgithubgithub.com/im-nymii/CVE-2025-59528★ 1githubgithub.com/UsifAraby/CVE-2025-59528-POC★ 1githubgithub.com/r3nsi15/Flowise-RCE-CVE-2025-59528★ 1githubgithub.com/mananispiwpiw/CVE-2025-59528-PoC★ 1githubgithub.com/maradonam18/-CVE-2025-59528-PoC★ 1githubgithub.com/vanhari/CVE-2025-59528★ 1githubgithub.com/Moon-Harvest/CVE-2025-59528★ 0githubgithub.com/corey-farley/CVE-2025-59528-Flowise-RCE★ 0vulncheckvulncheck.com/xdb/3f5adc61e864unverifiedvulncheckvulncheck.com/xdb/263b32bf8c69unverifiedvulncheckvulncheck.com/xdb/677b1c3dfb43unverifiedvulncheckvulncheck.com/xdb/1cbf1594891bunverifiedvulncheckvulncheck.com/xdb/2c30213b42e0unverifiedvulncheckvulncheck.com/xdb/563083701a16unverifiedvulncheckvulncheck.com/xdb/56a41c9860e4unverifiedvulncheckvulncheck.com/xdb/091dd29241cdunverifiedvulncheckvulncheck.com/xdb/0341f06a864funverifiedvulncheckvulncheck.com/xdb/2a1a4825b0c4unverifiedvulncheckvulncheck.com/xdb/783ea41601faunverifiedvulncheckvulncheck.com/xdb/ff5acae38c2aunverifiedvulncheckvulncheck.com/xdb/c66d7108f5e1unverifiedvulncheckvulncheck.com/xdb/808bec20af16unverifiedvulncheckvulncheck.com/xdb/4ea435a91d53unverifiedvulncheckvulncheck.com/xdb/584bb236151eunverifiedvulncheckvulncheck.com/xdb/407a5532a27cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L132https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L220https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L262-L270https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/controllers/nodes/index.ts#L57-L78https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/routes/node-load-methods/index.ts#L5https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/services/nodes/index.ts#L91-L94https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7p