Junglewise Threat Intelligence

CVE-2026-73602: Flowise vm2 sandbox escape to RCE

CVE-2026-73602 · Severity: critical · CVSS 9.9 · Published 2026-08-13

Technologies: FlowiseAI Flowise. Vendors: FlowiseAI.

Executive brief

Flowise is a low-code AI application platform that allows users to build chatbots and workflows through a drag-and-drop interface, including execution of custom JavaScript code in a sandboxed environment. A vulnerability in the JavaScript sandbox escape allows authenticated users to bypass path traversal protections and execute arbitrary code on the server, potentially compromising the entire platform and any data it processes.

Technical details

The vulnerability exists in Flowise's use of an outdated and deprecated vm2 JavaScript sandbox (version 3.9.25), which already contains known security issues (CVE-2026-22709). Additionally, Flowise exploits a weakness in the moment.js library's CVE-2022-24785 patch: the patch uses a regex match function to validate locale names, but an attacker can craft a fake String object with a custom match function that always returns true, bypassing the path traversal check. This allows an authenticated attacker to load and execute malicious JavaScript files from the document store outside the intended sandbox. The attack requires authentication and custom JavaScript execution capability, but once exploited, grants full remote code execution as the Node.js process user.

Affected products

  • FlowiseAI Flowise before 3.1.3

Timeline

  • 2026-04-10: disclosed: Vulnerability disclosed by elttam security researchers
  • 2026-07-29: advisory: GitHub Security Advisory GHSA-rqh4-rxw3-93rp published
  • 2026-08-13: patched: Flowise 3.1.3 released with patch; repository archived

References