Flowise's CVSS 10 RCE Nightmare: 12,000 Exposed AI Servers Under Siege
Open-source AI agent builders like Flowise were supposed to democratize intelligent automation. Instead, a perfect-score vulnerability has hackers knocking on 12,000 doors.
Threat DigestApr 07, 20264 min read
⚡ Key Takeaways
CVSS 10.0 RCE in Flowise's CustomMCP node allows arbitrary JS execution with full Node.js privileges.𝕏
Over 12,000 internet-exposed instances remain vulnerable despite a 6-month-old patch.𝕏
Third exploited Flowise flaw this year signals deeper architectural risks in AI agent builders.𝕏
The 60-Second TL;DR
CVSS 10.0 RCE in Flowise's CustomMCP node allows arbitrary JS execution with full Node.js privileges.
Over 12,000 internet-exposed instances remain vulnerable despite a 6-month-old patch.
Third exploited Flowise flaw this year signals deeper architectural risks in AI agent builders.