News

Attackers exploit critical Flowise flaw CVE-2025-59528 for remote code execution

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-04-07 20:16:05 UTC

Attackers are exploiting a critical Flowise flaw, tracked as CVE-2025-59528 (CVSS score of 10), that lets them run malicious code and access systems due to poor validation of user-supplied JavaScript. Attackers are actively exploiting a critical vulnerability…

Attackers exploit critical Flowise flaw CVE-2025-59528 for remote code execution Attackers are actively exploiting a critical vulnerability in Flowise, tracked as CVE-2025-59528, that allows remote … [+3613 chars]