Junglewise Threat Intelligence

CVE-2025-59528: FlowiseAI Flowise remote code execution in CustomMCP node

CVE-2025-59528 · Severity: low · CVSS 3.1 · Published 2025-09-15

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, a visual builder for AI agents and language model workflows, contains a critical vulnerability that allows remote attackers to execute arbitrary code on the server. By sending a specially crafted request to the CustomMCP node configuration, an attacker can take full control of the host system. This could lead to the theft of sensitive AI training data, exposure of API keys, or complete disruption of business operations.

Technical details

A remote code execution (RCE) vulnerability exists in Flowise version 3.0.5 due to improper input validation in the CustomMCP node. The vulnerability is located in the `convertToValidJSONString` function, which passes user-supplied input from the `mcpServerConfig` parameter directly into the JavaScript `Function()` constructor. Because this input is evaluated as code within the global Node.js context without sanitization, an attacker can use the `child_process` or `fs` modules to execute system commands or access the file system. Exploitation requires only network access to the `/api/v1/node-load-method/customMCP` endpoint and a valid API token. The issue is fixed in version 3.0.6.

Affected products

  • FlowiseAI flowise 3.0.5

Timeline

  • 2025-09-13: advisory: Original GitHub security advisory published
  • 2025-09-15: disclosed: Vulnerability disclosed via OSV database
  • 2025-09-22: other: NVD entry created
  • 2025-09-15: patched: Fix released in version 3.0.6

References

Related threats