Bleepingcomputer Critical Flowise RCE Vulnerability Exploited, Thousands of Systems at Risk
Article Content
- •CVE-2025-59528 allows arbitrary JavaScript code execution in Flowise due to improper input validation.
- •Exploitation attempts have been detected, with 12,000 to 15,000 vulnerable Flowise instances exposed online.
- •Users are recommended to upgrade to version 3.1.1 or at least 3.0.6 to protect against this vulnerability.
A critical remote code execution (RCE) vulnerability in the Flowise low-code platform, tracked as CVE-2025-59528, is being actively exploited by threat actors. This flaw allows attackers to inject arbitrary JavaScript code due to improper validation of user input in the CustomMCP node, which connects to external Model Context Protocol (MCP) servers. The vulnerability was first disclosed in September 2025, and despite a patch being available since version 3.0.6, exploitation attempts have been observed as of April 6, 2026. Security researchers estimate that between 12,000 and 15,000 instances of Flowise are currently exposed on the public internet, with exploitation activity originating from a single Starlink IP address. Additionally, two other vulnerabilities (CVE-2025-8943 and CVE-2025-26319) have also been flagged for active exploitation. Users are urged to upgrade to the latest version, 3.1.1, to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2025-26319 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…