/Vulnerability Library

Flowise - Remote Code Execution

CVE-2025-59528
Verified

Description

Flowise 3.0.5 contains a remote code execution vulnerability caused by unsafe evaluation of user input in the CustomMCP node's convertToValidJSONString function, letting remote attackers execute arbitrary code with full Node.js privileges, exploit requires user input to be processed by the vulnerable node.

Severity

Critical

CVSS Score

10

Exploit Probability

86%

Published Date

April 2, 2026

Template Author

xtr0nix

CVE-2025-59528.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-59528
CWE ID:
cwe-94

References

https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3gcm-f6qx-ff7phttps://nvd.nist.gov/vuln/detail/CVE-2025-59528

Remediation Steps

Update to version 3.0.6 or later.