CVE-2026-73602
EUVD-2026-5780613.08.2026, 12:17
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flowiseai | flowise | 𝑥 < 3.1.3 |
𝑥
= Vulnerable software versions