Sandbox Escape Vulnerability in Flowise by FlowiseAI
CVE-2026-73602

9CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73602?

A sandbox escape vulnerability found in Flowise prior to version 3.1.3 allows authenticated users to execute arbitrary code. This is achieved through a moment locale validation bypass, where attackers can create a malicious String object with an overridden match function. By doing so, they can evade path traversal protections and access JavaScript files stored outside the sandbox environment. This vulnerability poses significant risks, enabling attackers to manipulate the system and execute harmful scripts.

Affected Version(s)

Flowise 0 < 3.1.3

Flowise 3.1.3

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alex-elttam
.