Flowise's Perfect-Score Flaw CVE-2025-59528: Attackers Already Inside
Flowise users thought they had a quick path to LLM apps. Wrong. Attackers are chaining CVE-2025-59528 for remote code execution, turning dev tools into backdoors.
Flowise users thought they had a quick path to LLM apps. Wrong. Attackers are chaining CVE-2025-59528 for remote code execution, turning dev tools into backdoors.
Open-source AI agent builders like Flowise were supposed to democratize intelligent automation. Instead, a perfect-score vulnerability has hackers knocking on 12,000 doors.
Imagine your company's AI agent turning into a hacker's backdoor overnight. That's the stark reality for thousands of Flowise users right now.
12,000 to 15,000 Flowise servers sit exposed to the internet today. One max-severity RCE bug just lit up in active attacks—straight from a Starlink IP.