{"id":"CVE-2026-73483","aliases":["GHSA-9gvv-qjj3-2p6g"],"title":"Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium","summary":"Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium","severity":"critical","vendor":"flowise","product":"flowise","ecosystem":"npm","affected":["flowise <= 3.1.2","flowise-components <= 3.1.2"],"patched":["flowise 3.1.3","flowise-components 3.1.3"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:17:03Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-9gvv-qjj3-2p6g","references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9gvv-qjj3-2p6g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73483"},{"url":"https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-puppeteer"},{"url":"https://github.com/advisories/GHSA-9gvv-qjj3-2p6g"}],"tags":["ghsa","npm"],"epss":0.0074,"epssPercentile":0.53114,"ingestedAt":"2026-10-07T16:38:22.233Z","slug":"CVE-2026-73483","body":"## Overview\n\nFlowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the `vm2/@flowiseai/nodevm` JavaScript sandbox. An authenticated user with access to the `/api/v1/node-custom-function` endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's `file://` URL handling. In versions 3.0.8–3.1.2 exploitation requires `ALLOW_BUILTIN_DEP=true`; earlier versions are exploitable by default. Fixed in 3.1.3.\n\n## Affected packages\n\n- `flowise <= 3.1.2`\n- `flowise-components <= 3.1.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `flowise 3.1.3`\n- `flowise-components 3.1.3`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}