Description
============================================================================= Security Advisory elttam
Topic: Flowise JavaScript Sandbox Escape
Module: FlowiseAI/Flowise, FlowiseAI/nodevm Disclosed:
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.2
- Patched version(s): 3.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Flowise Sandbox Escape to RCE and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override - CVE-2026-69254
- Flowise RCE via TypeORM DataSource - CVE-2026-69251
- Flowise: Code Injection in CSVAgent leads to Authenticated RCE - CVE-2026-41137
- Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox - CVE-2026-41270
You might also like:
See something that needs correcting? Let us knowUpdated August 04, 2026


