Skip to content

CVE-2025-8943

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
April 7, 2026
Last Seen
April 8, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical remote code execution (RCE) vulnerability in the Flowise low-code platform, tracked as CVE-2025-59528, is being actively exploited by threat actors. This flaw allows attackers to inject arbitrary JavaScript code due to improper validation of user input in the CustomMCP node, which connect...

Public Exploits

Checking GitHub for proof-of-concept code…