天下漏洞,尽知其名
CRITICAL

CVE-2025-59528 Amoru-Bek 代码执行漏洞

影响攻击者可远程执行任意代码

AI 研判

Amoru-Bek 存在代码执行漏洞,对应 CVE-2025-59528,评级为 HIGH。公开信息仅提供了 GitHub 上的 PoC 链接,暂无更多技术细节。

影响范围

Amoru-Bek

受影响的具体产品版本范围暂无公开信息,无法确认。

漏洞详情

该漏洞属于代码执行类漏洞,成因与具体利用方式暂无公开信息。从公开的 PoC 仓库名称判断,攻击者可能通过构造特定请求触发代码执行。

利用条件与风险

利用前提条件与实战风险暂无公开信息,需结合具体部署环境评估。

修复建议

官方修复方案与临时缓解措施暂无公开信息,建议关注厂商公告并及时更新。

原始情报

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.