Sploitus

CVE-2025-59528

21 known exploits for CVE-2025-59528

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.

Affected products
Flowise
Flowiseai Flowise
= 3.0.5
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
90.2% (100th percentile)
Weakness
CWE-94
NVD status
Analyzed
Published
2025-09-22
CVE-2025-59528 at NVD
Authoritative description, scoring and affected products

21 known exploits for CVE-2025-59528

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Code Injection in Flowiseai Flowise
2026-08-09 LoaxertGITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-06-09 Moon-HarvestGITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-05-17 corey-farleyGITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-05-16 im-nymiiGITHUB
Exploit for Missing Authentication for Critical Function in Flowiseai Flowise
2026-05-14 ledksvGITHUB
Exploit for Missing Authentication for Critical Function in Flowiseai Flowise
2026-05-10 v3rycl0p3rGITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-05-01 mananispiwpiwGITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-04-15 maradonam18GITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-04-15 r3nsi15GITHUB
Exploit for Missing Authentication for Critical Function in Flowiseai Flowise
2026-04-14 honney336GITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-04-13 UsifArabyGITHUB
Exploit for Code Injection in Flowiseai Flowise
2026-04-13 vanhariGITHUB
Exploit for Missing Authentication for Critical Function in Flowiseai Flowise
2026-04-13 kartik2005221GITHUB
Exploit for Path Traversal in Gogs
2026-04-12 0dgtGITHUB
πŸ“„ Flowise 3.0.6 JS Parsing Injection
2025-12-11 indoushkaPACKETSTORMPHP
πŸ“„ Flowise 3.0.4 Code Injection
2025-11-27 indoushkaPACKETSTORMPHP
πŸ“„ Flowise JS Injection Remote Code Execution
2025-11-24 nltt0, Valentin Lobstein, Kim SooHyunPACKETSTORMRuby
πŸ“„ Flowise 3.0.4 Remote Command Execution
2025-11-03 nltt0PACKETSTORMPython
Exploit for Code Injection in Flowiseai Flowise
2025-11-02 zimshkGITHUB
Flowise 3.0.4 - Remote Code Execution (RCE)
2025-10-31 nltt0EXPLOITDBPython
Flowise JS Injection RCE
2025-09-13 Kim SooHyun (im-soohyun), nltt0, Valentin Lobstein <chocapikk@leakix.net>METASPLOITRuby