CVE-2025-59528: Flowise has Remote Code Execution vulnerability

Published Sep 15, 2025
·
Updated

Description

Cause of the Vulnerability

The CustomMCP node allows users to input configuration settings for connecting to an external MCP (Model Context Protocol) server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation.

Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as childprocess and fs.

Vulnerability Flow

1. User Input Received: Input is provided via the API endpoint /api/v1/node-load-method/customMCP through the mcpServerConfig parameter. 2. Variable Substitution: The substituteVariablesInString function replaces template variables like $vars.xxx, but no security filtering is applied during this step. 3. Dangerous Code Execution: The convertToValidJSONString function executes the input using Function('return ' + inputString)(). If the inputString contains malicious code, it gets executed in the global Node.js context, allowing actions such as command execution and file system access.

Taint Flow

- Taint 01: Route Registration index.ts (Line 5)

- Taint 02: Controller index.ts (Line 57–78)

- Taint 03: Service index.ts (Line 91–94)

- Taint 04: CustomMCP Node Entry Point CustomMCP.ts (Line 132)

- Taint 05: Variable Substitution CustomMCP.ts (Line 220)

- Taint 06: Dangerous Constructor Execution CustomMCP.ts (Line 262–270)

Proof of Concept (PoC)

bash curl -X POST http://localhost:3000/api/v1/node-load-method/customMCP \ -H "Content-Type: application/json" \ -H "Authorization: Bearer tmY1fIjgqZ6-nWUuZ9G7VzDtlsOiSZlDZjFSxZrDd0Q" \ -d '{ "loadMethod": "listActions", "inputs": { "mcpServerConfig": "({x:(function(){const cp = process.mainModule.require(\"childprocess\");cp.execSync(\"echo !!RCE-OK!! >/tmp/RCE.txt\");return 1;})()})" } }' <img width="1907" height="958" alt="image" src="https://github.com/user-attachments/assets/78b50eb1-67af-4c8b-97ea-7e2c05426962" />

When executed, this creates a file /tmp/RCE.txt on the server, confirming command execution.

Impact

Complete System Takeover and Infrastructure Threat

This vulnerability allows attackers to execute arbitrary JavaScript code on the Flowise server, leading to:

- Full system compromise - File system access - Command execution - Sensitive data exfiltration

As only an API token is required, this poses an extreme security risk to business continuity and customer data.

Other sources

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as childprocess and fs. This issue has been patched in version 3.0.6.

MITRE

Affected Software

2 affected componentsFixes available
npm/flowise=3.0.5
3.0.6
FlowiseAI Flowise=3.0.5

Event History

Sep 15, 2025
Advisory Published
via GitHub·07:59 PM
Data Sourced
via GitHub·07:59 PM
DescriptionSeverityWeaknessAffected Software
Sep 22, 2025
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 31, 2025
Exploit Published
12:00 AM
Known Exploited
10:46 AM
Apr 7, 2026
News Published
via BleepingComputer·05:02 PM
News Published
via BleepingComputer·05:03 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-59528?

CVE-2025-59528 has been rated as a high severity vulnerability due to its potential to allow unauthorized access to system configurations.

2

How do I fix CVE-2025-59528?

To mitigate CVE-2025-59528, update the Flowise package to version 3.0.6 or later.

3

What software versions are affected by CVE-2025-59528?

CVE-2025-59528 affects the Flowise package version 3.0.5 and below.

4

What is the cause of CVE-2025-59528?

The vulnerability arises from inadequate validation of user input in the 'CustomMCP' node, specifically in the mcpServerConfig string.

5

Can CVE-2025-59528 lead to a data breach?

Yes, CVE-2025-59528 could potentially allow an attacker to manipulate configurations, which may lead to a data breach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203