Skip to content

MCPA-2026-0054

criticalrce-vectors

Flowise RCE via NodeVM sandbox escape through nodeVMOptions override (CVE-2026-69254)

Flowise 3.1.2 and earlier let custom-code nodes override nodeVMOptions passed to executeJavaScriptCode(), escaping the NodeVM sandbox and executing arbitrary code on the host (reported by elttam). Fixed in 3.1.3.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.3
npmflowise-components
>= 0, < 3.1.3

Identifiers

CVE-2026-69254GHSA-3769-jgqc-cxm7CWE-94

References

Timeline

  • Published: 2026-08-04

← All advisories