A maximum-severity (CVSS 10.0) code-injection vulnerability, CVE-2025-59528, in the open-source Flowise AI agent-building platform allowed unauthenticated remote code execution via its CustomMCP node, which passed unsanitized user input directly into a JavaScript Function() constructor. A security canary network detected active exploitation on 7 April 2026, more than six months after the flaw was introduced, with attackers using it to execute arbitrary commands, harvest API keys and credentials, and fully compromise hosts across more than 12,000 internet-exposed Flowise instances. FlowiseAI patched the issue in version 3.0.6 and urged all self-hosted users to upgrade immediately.