NPM · AUGUST 2026 · CONFIRMED

Flowise Sandbox Escape Vulnerability: Critical RCE Threat Confirmed

GHSA-3769-JGQC-CXM7GHSA-VMV7-4M6C-3CG5Severity: HIGH

A confirmed high severity vulnerability in Flowise enables authenticated users to execute arbitrary system commands as root, affecting multiple versions of flowise and flowise-components.

What happened

A critical remote code execution (RCE) vulnerability has been confirmed in Flowise, tracked as GHSA-3769-JGQC-CXM7 and GHSA-VMV7-4M6C-3CG5. The vulnerability stems from a sandbox escape in the `executeJavaScriptCode()` function, which allows overriding default sandbox security settings via `nodeVMOptions`. This enables any authenticated user to execute arbitrary system commands as root on the Flowise server. Affected versions of flowise range from 0 to 3.1.3, with specific fixed versions noted. For flowise-components, affected versions range from 0 to 3.1.3. It is recommended to upgrade to the latest patched versions once available and review custom NodeVM configurations for potential security risks. Consult the primary sources for detailed version information and further guidance.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If flowise is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats