GHSA-6j9g-8fxc-25hqCritical· 8.8▾ MidnightDuplicate Advisory: Flowise contains an unauthenticated sandbox escape
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9gvv-qjj3-2p6g. This link is maintained to preserve external references.
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's file:// URL handling. In versions 3.0.8–3.1.2 exploitation requires ALLOW_BUILTIN_DEP=true; earlier versions are exploitable by default. Fixed in 3.1.3.
flowise <= 3.1.2flowise-components <= 3.1.2Upgrade to a patched release:
flowise 3.1.3flowise-components 3.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73483CriticalFlowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
CVE-2025-71336Critical· 9.8Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers
CVE-2026-91936Medium· 6.8Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks
CVE-2026-91931High· 8.5Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter
CVE-2026-73487CriticalFlowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
GHSA-w4hm-rrxg-pxcfMedium· 7.1Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability