Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation via MCP Server Config Injection — 12,000+ Instances Exposed
The Hacker News·high signal
VulnCheck detected first in-the-wild exploitation of CVE-2025-59528 (CVSS 10.0) in Flowise's CustomMCP node, which parses user-provided mcpServerConfig strings and executes JavaScript without validation, granting access to child_process and fs with full Node.js privileges. Attacks originate from a single Starlink IP, targeting 12,000-15,000 publicly exposed instances. This is Flowise's third CVE with confirmed in-the-wild exploitation. Patched in version 3.0.6.