critical AI Issue

Flowise AI Agent Builder RCE — Active In-The-Wild Exploitation

CVECVE-2025-59528
Severitycritical
Statusopen
DateApril 8, 2026
AffectsFlowise AI Agent Builder before 3.0.6 (12,000-15,000 exposed instances)
Sourcethehackernews.com

Details

CVSS 10.0. CustomMCP node executes user-provided JavaScript without security validation, running with full Node.js runtime privileges (child_process, fs). First in-the-wild exploitation detected by VulnCheck in April 2026 from a Starlink IP. Exploitable for 6+ months. Fix: Flowise 3.0.6.