Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-46442
9.4CRITICAL
What is CVE-2026-46442?
A design flaw in Flowise allows authenticated users to exploit the Custom JS Function node by submitting arbitrary JavaScript without route-level authorization. If not properly configured with E2B_APIKEY, the code executes in a NodeVM sandbox, which can be compromised. This compromise enables attackers to access the host process object, facilitating unauthorized execution of system commands via child_process. Flowise has addressed this issue in version 3.1.2, but prior versions remain vulnerable, highlighting the need for users to upgrade promptly.
Affected Version(s)
Flowise < 3.1.2
References
EPSS Score
36% chance of being exploited in the next 30 days.
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
