Agents
Flowise CVE-2025-59528 Under Active In-the-Wild Exploitation — Third Critical AI Agent Builder Flaw with 12,000+ Exposed Instances
VulnCheck confirmed the first in-the-wild exploitation of CVE-2025-59528 (CVSS 10.0) in Flowise, an open-source AI agent builder with 12,000+ internet-exposed instances. The flaw allows unauthenticated RCE through the CustomMCP node, which executes user-provided JavaScript without validation, granting access to child_process and fs with full Node.js privileges. Initial attacks originated from a single Starlink IP. This is Flowise's third exploited CVE, compounding the separate CVE-2026-40933 MCP adapter flaw. The pattern of AI agent builders shipping with dangerous code execution defaults is now a confirmed attack surface.
↳ Follow the thread