CVE-2026-73083

Source
https://cve.org/CVERecord?id=CVE-2026-73083
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73083.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73083
Aliases
  • GHSA-gr3h-c2j7-r52g
Published
2026-08-11T16:33:22Z
Modified
2026-09-11T03:30:21Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading
Details

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js require(), before the V8 isolate is applied. Top-level module code can therefore call require('child_process'), access fs, and use other Node.js APIs in the host engine process outside the sandbox. An authenticated user who can create a Code step can read environment secrets including AP_ENCRYPTION_KEY and AP_JWT_SECRET, read or write files, and reach internal services. This issue is fixed in version 0.80.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-693"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73083.json"
}
References

Affected packages

Git / github.com/activepieces/activepieces

Affected ranges

Type
GIT
Repo
https://github.com/activepieces/activepieces
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.80.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.1.3
0.15.0
0.15.0-rc.2
0.15.0-rc.3
0.15.0-rc.4
0.15.0-rc.5
0.15.0-rc.6
0.15.0-rc.7
0.15.0-rc.8
0.16.0
0.16.0-rc.1
0.16.0-rc.2
0.16.0-rc.3
0.17.0
0.18.0
0.18.0-rc.1
0.18.1
0.18.2
0.19.0
0.19.0-rc.1
0.19.0-rc.2
0.19.0-rc.3
0.19.0-rc.4
0.2.0
0.2.5
0.20.0
0.20.0-rc.2
0.20.0-rc.3
0.20.0-rc.4
0.20.1
0.20.2
0.20.3
0.21.0
0.21.0-rc.1
0.21.0-rc.2
0.21.0-rc.4
0.22.0-rc.1
0.22.0-rc.3
0.22.0-rc.4
0.23.0
0.23.0-rc.1
0.23.0-rc.2
0.24.0
0.24.1
0.25.0
0.25.1
0.26.0
0.26.0-rc.1
0.26.0-rc.2
0.26.0-rc.3
0.26.1
0.27.0
0.27.0-rc.1
0.27.0-rc.2
0.27.0-rc.3
0.27.0-rc.4
0.27.0-rc.5
0.27.0-rc.6
0.27.0-rc.7
0.27.0-rc.8
0.28.0
0.28.0-rc.1
0.29.0
0.29.0-rc.1
0.29.0-rc.3
0.29.1
0.3.15
0.3.3
0.3.5
0.3.6
0.30.0-rc.1
0.30.0-rc.3
0.30.0-rc.4
0.30.0-rc.5
0.30.0-rc.6
0.30.0-rc.7
0.30.0-rc.8
0.34.11
0.35.0
0.35.1
0.36.0
0.36.1
0.36.2
0.36.3
0.36.4
0.37.0
0.37.1
0.37.2
0.37.3
0.37.4
0.37.5
0.37.6
0.38.0
0.38.1
0.38.2
0.38.3
0.38.6
0.39.0
0.39.1
0.39.2
0.39.3
0.39.4
0.39.5
0.39.6
0.39.7
0.39.9
0.4.0
0.41.0
0.41.0-rc.1
0.42.0
0.42.0-rc.1
0.45.0
0.45.1
0.46.0
0.46.3
0.46.5
0.46.6
0.46.7
0.47.2
0.47.4
0.48.0
0.48.1
0.48.2
0.48.3
0.48.6
0.48.7
0.49.0
0.49.0-rc.0
0.50.0
0.50.1
0.50.10
0.50.11
0.50.12
0.50.2
0.50.3
0.50.4
0.50.5
0.50.7
0.50.8
0.50.9
0.53.0
0.53.1
0.54.0
0.56.0
0.57.0
0.57.1
0.59.0
0.60.0
0.60.2
0.63.0
0.64.0
0.64.0-rc.0
0.64.1
0.64.2
0.65.0
0.66.0
0.66.1
0.66.2
0.66.3
0.66.4
0.66.5
0.66.6
0.66.7
0.67.0
0.67.1
0.67.2
0.67.3
0.67.4
0.67.5
0.67.6
0.68.0
0.68.1
0.68.2
0.68.3
0.69.0
0.7.0
0.70.0
0.70.1
0.70.2
0.70.3
0.70.4
0.70.5
0.70.6
0.70.7
0.70.8
0.71.0
0.71.1
0.71.3
0.71.4
0.72.0
0.72.1
0.72.2
0.72.3
0.73.0
0.74.0
0.74.3
0.74.4
0.75.0
0.76.0
0.76.2
0.77.1
0.77.2
0.77.3
0.77.4
0.77.5
0.77.6
0.78.0
0.78.1
0.78.2
0.79.0
0.80.0-rc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73083.json"