A maximum-severity (CVSS 10) remote code execution vulnerability in Flowise, tracked as CVE-2025-59528, is now being actively exploited. The flaw exists in the CustomMCP node, which unsafely evaluates JavaScript from the mcpServerConfig input without validation. Originally disclosed last September and patched in version 3.0.6,

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:

Sort: