Vulnerabilities/

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

Severity:
High

Description

A sandbox escape vulnerability in executeJavaScriptCode() allows any authenticated user to execute arbitrary system commands as root on the Flowise server.

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-components
Anything's wrong? Let us know Last updated on August 04, 2026