Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-46442

9.4CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-46442?

A design flaw in Flowise allows authenticated users to exploit the Custom JS Function node by submitting arbitrary JavaScript without route-level authorization. If not properly configured with E2B_APIKEY, the code executes in a NodeVM sandbox, which can be compromised. This compromise enables attackers to access the host process object, facilitating unauthorized execution of system commands via child_process. Flowise has addressed this issue in version 3.1.2, but prior versions remain vulnerable, highlighting the need for users to upgrade promptly.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.