Critical RCE Vulnerability in Flowise AI Builder Exploited Despite 6-Month-Old Patch
A maximum severity code injection vulnerability (CVE-2025-59528) in Flowise AI agent builder allows unauthenticated attackers to execute arbitrary code with full system privileges using only an API token. Despite the vulnerability being patched in September 2025, over 12,000 instances remain vulnerable to active exploitation more than six months later. This demonstrates the critical gap between patch availability and deployment, particularly for internet-facing applications where delayed patching creates extended windows of exposure. Organizations running unpatched systems face immediate risk of complete system compromise, data theft, and potential lateral movement within their networks.
Tactical Insight
Immediate actions
- Upgrade all Flowise instances to version 3.0.6 or later immediately
- Conduct emergency inventory scan for all AI/ML platforms and development tools
- Implement network access controls to limit exposure of vulnerable instances
Long-term improvements
- Establish automated patch management processes with defined SLAs for critical vulnerabilities
- Deploy vulnerability scanning tools to continuously monitor internet-facing applications
- Create asset inventory management system to track all software versions and dependencies
Detection measures
- Monitor API usage patterns for suspicious authentication attempts or unusual code execution
- Implement network monitoring to detect unauthorized outbound connections from affected systems