GHSA-9gvv-qjj3-2p6g

Suggest an improvement
Source
https://github.com/advisories/GHSA-9gvv-qjj3-2p6g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9gvv-qjj3-2p6g/GHSA-9gvv-qjj3-2p6g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9gvv-qjj3-2p6g
Aliases
Published
2026-10-07T16:17:02Z
Modified
2026-10-07T16:30:05Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
Details

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's file:// URL handling. In versions 3.0.8–3.1.2 exploitation requires ALLOW_BUILTIN_DEP=true; earlier versions are exploitable by default. Fixed in 3.1.3.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T16:17:02Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

npm / flowise

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3

Database specific

last_known_affected_version_range
"<= 3.1.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9gvv-qjj3-2p6g/GHSA-9gvv-qjj3-2p6g.json"

npm / flowise-components

Package

Name
flowise-components
View open source insights on deps.dev
Purl
pkg:npm/flowise-components

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3

Database specific

last_known_affected_version_range
"<= 3.1.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9gvv-qjj3-2p6g/GHSA-9gvv-qjj3-2p6g.json"