CriticalVulnerability
GHSA-9gvv-qjj3-2p6g: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
- Identifiers
- CVE-2026-73483GHSA-9gvv-qjj3-2p6g
- Published
- Record updated
Summary
Flowise versions 3.1.2 and earlier (packages flowise and flowise-components) contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can supply attacker-controlled executablePath and args to puppeteer.launch(), which invokes child_process.spawn() outside the sandbox, enabling arbitrary OS command execution as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's file:// handling. Versions 3.0.8 to 3.1.2 require ALLOW_BUILTIN_DEP=true for exploitation; earlier versions are exploitable by default.
Mitigation
Fixed in 3.1.3.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database