Description
A sandbox escape vulnerability in executeJavaScriptCode() allows any authenticated user to execute arbitrary system commands as root on the Flowise server.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.2
- Patched version(s): 3.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise Sandbox Escape to RCE - CVE-2026-69253
- Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox - CVE-2026-41270
- Flowise: Authenticated RCE Via MCP Adapters - CVE-2026-40933
- Flowise RCE via SQLite Record Manager Node - CVE-2026-69259


