Active Exploitation of Flowise CustomMCP RCE Exposes Thousands of Internet-Facing Instances
Threat actors are actively exploiting CVE-2025-59528, a CVSS 10.0 remote code execution flaw in the open-source AI platform Flowise. The bug affects Flowise versions through 3.0.5 and stems from the CustomMCP node unsafely passing user-controlled input into JavaScript execution, allowing attackers with an API token to run arbitrary code with full Node.js runtime privileges. Researchers said the issue can be triggered remotely via a crafted HTTP POST request without user interaction, leading to operating system command execution, filesystem access, sensitive data theft, and full system compromise.
Security researchers observed in-the-wild exploitation originating from a single Starlink IP address, while warning that roughly 12,000 to 15,000 internet-exposed Flowise instances sharply expand the attack surface for opportunistic attacks. Flowise disclosed the vulnerability in 2025, credited researcher Kim SooHyun, and patched the flaw in version 3.0.6. The incident marks the third Flowise vulnerability reported as exploited in the wild after CVE-2025-8943 and CVE-2025-26319, increasing pressure on organizations to upgrade immediately and limit public exposure of Flowise APIs.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
6 events from the most recent confirmed update back to the earliest known activity.
OX Security discloses broader MCP design flaw impacting Flowise and AI tools
OX Security disclosed a critical remote command execution exposure tied to architectural flaws in Anthropic's MCP SDKs, affecting Flowise and multiple other AI frameworks rather than a single-product bug. The researchers reported successful command execution on six production platforms, identified several exploitation families, and said at least ten CVEs had been issued across affected products.
VulnCheck flags two more Flowise flaws under active exploitation
VulnCheck reported that two additional critical Flowise vulnerabilities, CVE-2025-8943 and CVE-2025-26319, were also being actively exploited. The company said it was providing customers with exploitation data and defensive artifacts including a PCAP, YARA rule, network signatures, and a target Docker container.
Researchers warn 12,000-15,000 internet-exposed Flowise instances are at risk
Security reporting highlighted that roughly 12,000 to 15,000 Flowise instances were exposed to the public internet, increasing the likelihood of opportunistic attacks. The exposure amplified the impact of the actively exploited RCE flaw.
VulnCheck observes in-the-wild exploitation of CVE-2025-59528
In April 2026, VulnCheck reported active exploitation of CVE-2025-59528 against Flowise instances. The observed activity was initially traced to a single Starlink IP address.
Flowise fixes CVE-2025-59528 in version 3.0.6
Flowise released a fix for CVE-2025-59528 in npm package version 3.0.6. The vulnerability affects versions up to 3.0.5 and can enable remote code execution through unsafe execution of user-supplied JavaScript.
Flowise discloses CVE-2025-59528 and credits researcher Kim SooHyun
Flowise disclosed CVE-2025-59528, a maximum-severity code injection flaw in the CustomMCP node, in September 2025. The issue was credited to researcher Kim SooHyun.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
10 references tracked. Mallory keeps watching after this page renders.
Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters
cybersecuritynews.com
Open sourceFlowise RCE Vulnerability CVE-2025-59528 Exploited Now
thecyberexpress.com
Open sourceHackers exploit a critical Flowise flaw affecting thousands of AI workflows | CSO Online
csoonline.com
Open sourceActive exploitation of max severity Flowise bug threatens broad compromise | brief | SC Media
scworld.com
Open sourceFlowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
thehackernews.com
Open sourceCVE-2025-59528: Flowise CustomMCP Code Injection RCE - TheCyberThrone
thecyberthrone.in
Open sourceMax severity Flowise RCE vulnerability now exploited in attacks
bleepingcomputer.com
Open sourceRCE in FlowiseAI/Flowise · Advisory · FlowiseAI/Flowise · GitHub
github.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


