Flowise - Remote Code Execution
CVE-2025-59528
Verified
Description
Flowise 3.0.5 contains a remote code execution vulnerability caused by unsafe evaluation of user input in the CustomMCP node's convertToValidJSONString function, letting remote attackers execute arbitrary code with full Node.js privileges, exploit requires user input to be processed by the vulnerable node.
Severity
Critical
CVSS Score
10
Exploit Probability
86%
Published Date
April 2, 2026
Template Author
xtr0nix
CVE-2025-59528.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-59528
CWE ID:
cwe-94
Remediation Steps
Update to version 3.0.6 or later.