Junglewise Threat Intelligence

CVE-2026-69253: Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-t

CVE-2026-69253 · Severity: high · CVSS 8.8 · Published 2026-08-04

Technologies: FlowiseAI Flowise, flowise (npm), flowise-components (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is an open-source low-code platform for building AI applications with drag-and-drop workflows that can execute custom JavaScript code in a sandbox. An attacker with the ability to inject malicious JavaScript into a Custom Function Agent Flow node or Custom Tool can escape the sandbox and gain remote code execution on the server. This allows complete compromise of the server running Flowise and access to any data or systems it can reach.

Technical details

The vulnerability is a sandbox escape in Flowise's use of the deprecated vm2 library to isolate custom JavaScript code. The root cause is that vm2 executes code in the same Node.js process, making true isolation impossible. Attackers can bypass the moment library's CVE-2022-24785 path-traversal patch by providing an object with a custom match() function that always returns true, allowing directory traversal. By combining this with the allowed moment dependency, an attacker can load arbitrary files and achieve RCE. The vulnerability requires the ability to inject JavaScript into a Custom Function Agent or Custom Tool node. Flowise has patched this by switching to the E2B sandbox in version 3.1.3, which properly isolates execution in a separate environment.

Affected products

  • FlowiseAI Flowise <=3.1.2
  • FlowiseAI flowise-components <=3.1.2

Timeline

  • 2026-04-11: disclosed: Vulnerability disclosed by Luke Jahnke and Alex Brown
  • 2026-07-29: advisory: GitHub security advisory GHSA-wg86-r78f-74mp published
  • 2026-08-04: patched: Patch released in version 3.1.3 switching to E2B sandbox

References

Related threats