CVE-2025-59528 is a critical remote code execution (RCE) vulnerability affecting Flowise version 3.0.5, a drag-and-drop UI for building large language model flows. The flaw resides in the CustomMCP node, where user-provided configuration strings are directly executed as JavaScript code without validation, leveraging the Node.js Function() constructor. This allows attackers to execute arbitrary code with full Node.js runtime privileges, including access to sensitive modules like child_process and fs. The vulnerability carries a CVSS score of 10.0 (CRITICAL), indicating an easily exploitable network-based attack with no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. Its high EPSS score of 0.83004 and FAUCET Risk Score of 100/100 further emphasize its severe potential impact. Exploitation is highly probable, with a Metasploit module (Flowise JS Injection RCE) and an ExploitDB entry (EDB-52440) publicly available. While not yet confirmed on the KEV catalog, there is community discussion and a Mastodon post highlighting the urgency of patching to version 3.0.6 to mitigate this severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.5CPE matchmatch criteria | cpe:2.3:a:flowiseai:flowise:3.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.