Flowise JS Injection RCE
PoC files
1 fileFile viewing is interactive and short-lived. Downloads are password-protected ZIP archives using password eip.
Analysis
Technical assessment
A Metasploit exploit module that achieves remote code execution on Flowise servers by injecting JavaScript code into the mcpServerConfig parameter of the /api/v1/node-load-method/customMCP endpoint, leveraging the convertToValidJSONString function's use of Function() to execute arbitrary commands via child_process.exec.
Backdoor review
No backdoor observed in reviewed code
The Metasploit module exploits a documented CVE-2025-59528 code injection vulnerability in Flowise. It sends a crafted JavaScript payload to the vulnerable endpoint to execute the user-supplied Metasploit payload. No concealed backdoor, unrelated remote access, persistence, or deceptive behavior was observed.
Classification basis and observed behavior
Classification basis
The module constructs and delivers a payload that executes arbitrary commands on the target via code injection, which is the definition of an exploit. It does not merely detect the vulnerability; it actively exploits it to achieve remote code execution.
modules/exploits/multi/http/flowise_js_rce.rb:120-135modules/exploits/multi/http/flowise_js_rce.rb:138-140Requirements
- Target must be running a vulnerable Flowise version (>= 2.2.7-patch.1 and < 3.0.6).
modules/exploits/multi/http/flowise_js_rce.rb:19-20 - For versions < 3.0.1, authentication may not be required if FLOWISE_USERNAME and FLOWISE_PASSWORD are not set.
modules/exploits/multi/http/flowise_js_rce.rb:23-25
Observed behavior
- Sends an HTTP request to the /api/v1/node-load-method/customMCP endpoint with a crafted mcpServerConfig parameter containing JavaScript code that uses child_process.exec to run an attacker-supplied command.
modules/exploits/multi/http/flowise_js_rce.rb:120-135 - Executes a Metasploit payload (e.g., reverse shell) on the target system by passing payload.encoded to the execute_command method.
modules/exploits/multi/http/flowise_js_rce.rb:138-140
Behaviors behind the backdoor verdict
Observables
- Exploit Mechanism
- JavaScript code injection via mcpServerConfig parameter using child_process.execThe module constructs a JavaScript payload that uses process.mainModule.require('child_process').exec() to run the attacker-chosen command, consistent with the described CVE-2025-59528 vulnerability.
modules/exploits/multi/http/flowise_js_rce.rb:120-121 - Target Behavior
- Executes Metasploit payload.encoded via execute_commandThe exploit method calls execute_command(payload.encoded), which is standard Metasploit exploit behavior to deliver the user-selected payload.
modules/exploits/multi/http/flowise_js_rce.rb:138-139
What the analysis did not establish
- Only the module source code and metadata are provided; framework mixins (e.g., Msf::Exploit::Remote::HTTP::Flowise) and payloads are not expanded, so the exact HTTP request construction and authentication flow are not fully visible.
- The evidence does not include any execution output or proof that the exploit was successfully run against a live target.
- Only the module source and metadata were reviewed; framework mixins (e.g., Msf::Exploit::Remote::HTTP::Flowise) and external payloads were not expanded or inspected.
- Binary files were flagged as metadata-only and not analyzed, but no binary files were present in the evidence.
This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.