{"data":{"id":"5d60ea86-765c-4612-a285-f66230a9e617","title":"GHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium","summary":"Flowise versions 3.1.2 and earlier (packages flowise and flowise-components) contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can supply attacker-controlled executablePath and args to puppeteer.launch(), which invokes child_process.spawn() outside the sandbox, enabling arbitrary OS command execution as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's file:// handling. Versions 3.0.8 to 3.1.2 require ALLOW_BUILTIN_DEP=true for exploitation; earlier versions are exploitable by default.","solution":"Fixed in 3.1.3.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-9gvv-qjj3-2p6g","publishedAt":"2026-10-07T16:17:02.000Z","cveId":"CVE-2026-73483","cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["other"],"issueType":"vulnerability","affectedPackages":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"affectedPackageNames":["flowise-components","flowise"],"affectedPackageRefs":["npm:flowise","npm:flowise-components"],"affectedVendors":[],"affectedVendorsRaw":["Flowise"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00621,"epssCheckedAt":"2026-10-10T06:41:58.184Z","kevDateAdded":null,"advisoryAliases":["GHSA-9gvv-qjj3-2p6g"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-07T16:17:02.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]}}