CVE-2026-73483Critical▾ MidnightFlowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.7%
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's file:// URL handling. In versions 3.0.8–3.1.2 exploitation requires ALLOW_BUILTIN_DEP=true; earlier versions are exploitable by default. Fixed in 3.1.3.
flowise <= 3.1.2flowise-components <= 3.1.2Upgrade to a patched release:
flowise 3.1.3flowise-components 3.1.3Connected by shared product, vendor, weakness, or advisory.
GHSA-6j9g-8fxc-25hqCritical· 8.8Duplicate Advisory: Flowise contains an unauthenticated sandbox escape
CVE-2026-73487CriticalFlowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
GHSA-w4hm-rrxg-pxcfMedium· 7.1Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability
CVE-2026-56275Medium· 7.1Flowise Execute Flow function has an SSRF vulnerability
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2024-58351HighFlowise OverrideConfig security vulnerability