CVE-2025-59528: falha crítica em FlowiseAI Flowise
Flowise has Remote Code Execution vulnerability
Publicada em
100Vexday Risk Score
Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.
ssvc Actcvss 10epss 86%
da publicação à arma39 dias
Publicada no NVD22 de set.
1ª PoC+39d
metasploit13 de set.
VulnCheck+195d
probabilidade de exploração
86%top 1% das CVEs
exploração observada
simVulnCheck
34 exploit(s) público(s)
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
FlowiseAI · FlowisePoCs públicas encontradas — 34
exploitdbwww.exploit-db.com/exploits/52440não verificadogithubgithub.com/r3nsi15/Flowise-RCE-CVE-2025-59528★ 1githubgithub.com/hackpatato/PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability★ 1githubgithub.com/corey-farley/CVE-2025-59528-Flowise-RCE★ 1githubgithub.com/NymiiTechTips/CVE-2025-59528★ 1githubgithub.com/arensballiu/Flowise-RCE-CVE-2025-59528★ 1githubgithub.com/UsifAraby/CVE-2025-59528-POC★ 1githubgithub.com/vanhari/CVE-2025-59528★ 1githubgithub.com/im-nymii/CVE-2025-59528★ 1githubgithub.com/maradonam18/-CVE-2025-59528-PoC★ 1githubgithub.com/mananispiwpiw/CVE-2025-59528-PoC★ 1githubgithub.com/zimshk/CVE-2025-59528.yaml★ 0githubgithub.com/Moon-Harvest/CVE-2025-59528★ 0githubgithub.com/Amoru-Bek/CVE-2025-59528-Poc★ 0githubgithub.com/Loaxert/CVE-2025-59528-PoC★ 0githubgithub.com/sonnelon/CVE-2025-59528-PoC★ 0vulncheckvulncheck.com/xdb/2c30213b42e0não verificadovulncheckvulncheck.com/xdb/563083701a16não verificadovulncheckvulncheck.com/xdb/56a41c9860e4não verificadovulncheckvulncheck.com/xdb/407a5532a27cnão verificadovulncheckvulncheck.com/xdb/584bb236151enão verificadovulncheckvulncheck.com/xdb/4ea435a91d53não verificadovulncheckvulncheck.com/xdb/ff5acae38c2anão verificadovulncheckvulncheck.com/xdb/808bec20af16não verificadovulncheckvulncheck.com/xdb/783ea41601fanão verificadovulncheckvulncheck.com/xdb/091dd29241cdnão verificadovulncheckvulncheck.com/xdb/0341f06a864fnão verificadovulncheckvulncheck.com/xdb/2a1a4825b0c4não verificadovulncheckvulncheck.com/xdb/9afe29efcd3bnão verificadovulncheckvulncheck.com/xdb/c66d7108f5e1não verificadovulncheckvulncheck.com/xdb/3f5adc61e864não verificadovulncheckvulncheck.com/xdb/263b32bf8c69não verificadovulncheckvulncheck.com/xdb/677b1c3dfb43não verificadovulncheckvulncheck.com/xdb/1cbf1594891bnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — FlowiseAI Flowise
No mesmo produto, das mais perigosas para as menos.
CVE-2025-58434CRITICALFlowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account TakeoverEPSS 49.9%CVE-2024-8181CRITICALFlowise Authentication BypassEPSS 45.1%CVE-2025-50538HIGHCVE-2025-50538EPSS 14.0%CVE-2024-8182HIGHFlowise Denial of ServiceEPSS 13.9%CVE-2025-61913CRITICALFlowise is vulnerable to arbitrary file read, arbitrary file writeEPSS 13.0%CVE-2025-61687HIGHFlowiseAI/Flosise has File Upload vulnerabilityEPSS 11.1%
Referências
https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L132https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L220https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/components/nodes/tools/MCP/CustomMCP/CustomMCP.ts#L262-L270https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/controllers/nodes/index.ts#L57-L78https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/routes/node-load-methods/index.ts#L5https://github.com/FlowiseAI/Flowise/blob/5930f1119c655bcf8d2200ae827a1f5b9fec81d0/packages/server/src/services/nodes/index.ts#L91-L94https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.0.6https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7p