Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-46442
9.4CRITICAL
What is CVE-2026-46442?
A design flaw in Flowise allows authenticated users to exploit the Custom JS Function node by submitting arbitrary JavaScript without route-level authorization. If not properly configured with E2B_APIKEY, the code executes in a NodeVM sandbox, which can be compromised. This compromise enables attackers to access the host process object, facilitating unauthorized execution of system commands via child_process. Flowise has addressed this issue in version 3.1.2, but prior versions remain vulnerable, highlighting the need for users to upgrade promptly.
Affected Version(s)
Flowise < 3.1.2
