---
id: CVE-2026-73483
aliases:
  - GHSA-9gvv-qjj3-2p6g
title: >-
  Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and
  arbitrary file read via Chromium
summary: >-
  Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and
  arbitrary file read via Chromium
severity: critical
vendor: flowise
product: flowise
ecosystem: npm
affected:
  - flowise <= 3.1.2
  - flowise-components <= 3.1.2
patched:
  - flowise 3.1.3
  - flowise-components 3.1.3
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T16:17:03Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-9gvv-qjj3-2p6g'
references:
  - url: >-
      https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-9gvv-qjj3-2p6g
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73483'
  - url: >-
      https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-puppeteer
  - url: 'https://github.com/advisories/GHSA-9gvv-qjj3-2p6g'
tags:
  - ghsa
  - npm
epss: 0.0074
epssPercentile: 0.53114
ingestedAt: '2026-10-07T16:38:22.233Z'
---

## Overview

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the `vm2/@flowiseai/nodevm` JavaScript sandbox. An authenticated user with access to the `/api/v1/node-custom-function` endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's `file://` URL handling. In versions 3.0.8–3.1.2 exploitation requires `ALLOW_BUILTIN_DEP=true`; earlier versions are exploitable by default. Fixed in 3.1.3.

## Affected packages

- `flowise <= 3.1.2`
- `flowise-components <= 3.1.2`

## Remediation

Upgrade to a patched release:

- `flowise 3.1.3`
- `flowise-components 3.1.3`
