{"id":"GHSA-6j9g-8fxc-25hq","title":"Duplicate Advisory: Flowise contains an unauthenticated sandbox escape","summary":"Duplicate Advisory: Flowise contains an unauthenticated sandbox escape","severity":"critical","cvss":8.8,"cwe":["CWE-78"],"vendor":"flowise","product":"flowise","ecosystem":"npm","affected":["flowise <= 3.1.2","flowise-components <= 3.1.2"],"patched":["flowise 3.1.3","flowise-components 3.1.3"],"published":"2026-08-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:16:49Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-6j9g-8fxc-25hq","references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9gvv-qjj3-2p6g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73483"},{"url":"https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-puppeteer"},{"url":"https://github.com/advisories/GHSA-6j9g-8fxc-25hq"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-07T16:38:22.234Z","slug":"GHSA-6j9g-8fxc-25hq","body":"## Overview\n\n# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-9gvv-qjj3-2p6g. This link is maintained to preserve external references.\n\n# Original Description\n\nFlowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the `vm2/@flowiseai/nodevm` JavaScript sandbox. An authenticated user with access to the `/api/v1/node-custom-function` endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's `file://` URL handling. In versions 3.0.8–3.1.2 exploitation requires `ALLOW_BUILTIN_DEP=true`; earlier versions are exploitable by default. Fixed in 3.1.3.\n\n## Affected packages\n\n- `flowise <= 3.1.2`\n- `flowise-components <= 3.1.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `flowise 3.1.3`\n- `flowise-components 3.1.3`","depth":"midnight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}