By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
Computing

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

News Room
Last updated: 2026/04/07 at 2:11 AM
News Room Published 7 April 2026
Share
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
SHARE

Ravie LakshmananApr 07, 2026Artificial Intelligence / Vulnerability

Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck.

The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution.

“The CustomMCP node allows users to input configuration settings for connecting to an external MCP (Model Context Protocol) server,” Flowise said in an advisory released in September 2025. “This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation.”

Flowise noted that successful exploitation of the vulnerability can allow access to dangerous modules such as child_process (command execution) and fs (file system), as it runs with full Node.js runtime privileges.

Put differently, a threat actor who weaponizes the flaw can execute arbitrary JavaScript code on the Flowise server, leading to full system compromise, file system access, command execution, and sensitive data exfiltration.

“As only an API token is required, this poses an extreme security risk to business continuity and customer data,” Flowise added. It credited Kim SooHyun with discovering and reporting the flaw. The issue was addressed in version 3.0.6 of the npm package.

According to details shared by VulnCheck, exploitation activity against the vulnerability has originated from a single Starlink IP address. CVE-2025-59528 is the third Flowise flaw with in-the-wild exploitation after CVE-2025-8943 (CVSS score: 9.8), an operating system command remote code execution, and CVE-2025-26319 (CVSS score: 8.9), an arbitrary file upload.

“This is a critical-severity bug in a popular AI platform used by a number of large corporations,” Caitlin Condon, vice president of security research at VulnCheck, told The Hacker News in a statement.

“This specific vulnerability has been public for more than six months, which means defenders have had time to prioritize and patch the vulnerability. The internet-facing attack surface area of 12,000+ exposed instances makes the active scanning and exploitation attempts we’re seeing more serious, as it means attackers have plenty of targets to opportunistically reconnoiter and exploit.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Update turns some Pixel units into expensive paperweights and Google has yet to respond Update turns some Pixel units into expensive paperweights and Google has yet to respond
Next Article Cryptocurrency News: Pepeto Outperforms LINK and AVAX as Kiyosaki Urges Buying Cryptocurrency News: Pepeto Outperforms LINK and AVAX as Kiyosaki Urges Buying
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Think Twice Before Wearing Your Headphones Outside – Here’s Why – BGR
Think Twice Before Wearing Your Headphones Outside – Here’s Why – BGR
News
China Post Group ventures into drone sector · TechNode
China Post Group ventures into drone sector · TechNode
Computing
Check out this bizarre Google Wallet bug causing the app to flicker wildly
Check out this bizarre Google Wallet bug causing the app to flicker wildly
News
Corvette recall: GM pulls vehicles over faulty software issue
Corvette recall: GM pulls vehicles over faulty software issue
Software

You Might also Like

China Post Group ventures into drone sector · TechNode
Computing

China Post Group ventures into drone sector · TechNode

1 Min Read

My Pinterest Income Breakdown — 10 Ways I Actually Make Money From Pins – Digital Marketing

11 Min Read
How to Get More Views on TikTok |
Computing

How to Get More Views on TikTok |

6 Min Read
OpenAI Releases Industrial Policy Blueprint: AI Tax, Public Wealth Fund, and a New Social Contract for the Intelligence Age – Chat GPT AI Hub
Computing

OpenAI Releases Industrial Policy Blueprint: AI Tax, Public Wealth Fund, and a New Social Contract for the Intelligence Age – Chat GPT AI Hub

11 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?