Executive brief
FlowiseAI is vulnerable to an authenticated remote code execution (RCE) flaw due to missing authorization checks and a sandbox escape in the custom JS function node.
Affected products
- npm flowise
Junglewise Threat Intelligence
Severity: critical · CVSS 9.9 · Published 2026-05-14
Technologies: flowise (npm). Vendors: npm.
FlowiseAI is vulnerable to an authenticated remote code execution (RCE) flaw due to missing authorization checks and a sandbox escape in the custom JS function node.