Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Flowise AI Agent Builder Under Active Exploitation via CVSS 10.0 Remote Code Execution Vulnerability
00

Flowise AI Agent Builder Under Active Exploitation via CVSS 10.0 Remote Code Execution Vulnerability

Apr 8, 2026

The Flowise AI agent builder platform faces active exploitation of CVE-2025-59528, a critical remote code execution vulnerability with the maximum CVSS score of 10.0 discovered by security researcher Kim SooHyun. The flaw in Flowise's CustomMCP node allows attackers with only an API token to inject code and access dangerous Node.js modules like child_process, enabling full system compromise, command execution, and data exfiltration. Security firm VulnCheck identified exploitation attempts from a Starlink IP address targeting the over 12,000 Flowise instances exposed on the internet, more than six months after the vulnerability became public in September 2025. Flowise patched the issue in version 3.0.6, but the vulnerability represents the third instance of in-the-wild exploitation affecting the platform used by numerous large corporations.

Critical Vulnerability in Flowise AI Platform

  • ▪CVE-2025-59528 was addressed in version 3.0.6 of the Flowise npm package
  • ▪CVE-2025-59528 is a code injection vulnerability in Flowise with a CVSS score of 10.0
  • ▪CVE-2025-59528 allows access to dangerous Node.js modules such as child_process and fs because it runs with full Node.js runtime privileges
  • ▪Exploitation of CVE-2025-59528 can lead to full system compromise, file system access, command execution, and sensitive data exfiltration
  • ▪Kim SooHyun discovered and reported CVE-2025-59528 to Flowise
  • ▪CVE-2025-59528 requires only an API token for exploitation
  • ▪Flowise released an advisory about CVE-2025-59528 in September 2025

Active Exploitation and Exposed Attack Surface

  • ▪Exploitation activity against CVE-2025-59528 has originated from a single Starlink IP address
  • ▪Threat actors are actively exploiting CVE-2025-59528 in Flowise according to VulnCheck findings
  • ▪CVE-2025-59528 has been public for more than six months as of April 2026

Pattern of Security Flaws in Flowise

  • ▪CVE-2025-8943 is an operating system command remote code execution vulnerability in Flowise with a CVSS score of 9.8
  • ▪CVE-2025-26319 is an arbitrary file upload vulnerability in Flowise with a CVSS score of 8.9
  • ▪CVE-2025-59528 is the third Flowise vulnerability with in-the-wild exploitation

Perspective of VulnCheck

  • ▪VulnCheck identified active exploitation of CVE-2025-59528 targeting Flowise instances in the wild
  • ▪VulnCheck's findings indicate threat actors are targeting the over 12,000 exposed Flowise instances with CVE-2025-59528 exploits

Perspective of Kim SooHyun

  • ▪Kim SooHyun followed responsible disclosure practices by reporting CVE-2025-59528 to Flowise before public disclosure

Perspective of Flowise users at large corporations

  • ▪Large corporations using Flowise face potential full system compromise and sensitive data exfiltration through CVE-2025-59528
  • ▪Flowise users must upgrade to version 3.0.6 or later to protect against CVE-2025-59528 exploitation

Perspective of Flowise Project

  • ▪Flowise has experienced three separate vulnerabilities with confirmed in-the-wild exploitation as of April 2026
  • ▪Flowise developers patched CVE-2025-59528 by releasing version 3.0.6 of the npm package following Kim SooHyun's report

1 source

Thehackernews
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
View source article

Featured stories

View more in AI security

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

Story comments

Loading comments…

Related entities

Node.js

Topics

AI securityOpen release risks & safetyAI agents

Featured stories

View more in AI security

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources