Patch Commitpatch
https://github.com/FlowiseAI/Flowise/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5 CVE-2026-73602
CRITICAL
Flowise before 3.1.3 Sandbox Escape to RCE
Record summary
CVE-2026-73602 has a selected CVSS score of 9.0 (critical).
Description
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.3 | affected |
| 3.1.3 | unaffected |
References
4GitHub Security Advisory (GHSA-rqh4-rxw3-93rp)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-rqh4-rxw3-93rp nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73602 VulnCheck Advisory: Flowise before 3.1.3 Sandbox Escape to RCEThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-to-rce