CVE-2026-73483: Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the `vm2/@flowiseai/nodevm` JavaScript sandbox. An authenticated user with access to the `/api/v1/node-custom-function` endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the sandbox boundary. This allows execution of arbitrary OS commands as the Flowise process user (root in the official Docker image) and arbitrary host file disclosure via Chromium's `file://` URL handling. In versions 3.0.8–3.1.2 exploitation requires `ALLOW_BUILTIN_DEP=true`; earlier versions are exploitable by default. Fixed in 3.1.3.
Recommended action
Recommended action
Upgrade affected packages to a patched version: flowise 3.1.3, flowise-components 3.1.3.
Technical details
- Vendor
- Not specified
- Product
- flowise, flowise-components
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source