← Blog · · df00tech

Flowise NodeVM Sandbox Escape Enables Authenticated RCE via Puppeteer (CVE-2026-73483)

breaking ghsa npm CVE-2026-73483

What happened

A GitHub Security Advisory (GHSA-9gvv-qjj3-2p6g) discloses a sandbox escape in Flowise, an open-source LLM orchestration platform, affecting the flowise and flowise-components packages in versions up to and including 3.1.2. The flaw sits in the vm2/@flowiseai/nodevm JavaScript sandbox used by the /api/v1/node-custom-function endpoint. An authenticated user can supply attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally calls child_process.spawn() outside the sandbox boundary. This yields arbitrary OS command execution as the Flowise process user — root, in the official Docker image — plus arbitrary host file disclosure via Chromium's file:// URL handling. Versions 3.0.8–3.1.2 require ALLOW_BUILTIN_DEP=true to be exploitable; earlier versions are exploitable by default. The issue is fixed in 3.1.3, and a public PoC reportedly exists.

Why it matters

This is authenticated RCE, not a theoretical sandbox weakness — any user with access to the custom-function node can break out of the intended JS sandbox and run commands with the privileges of the Flowise process, which in the default Docker deployment is root. Organizations running self-hosted Flowise for internal LLM workflows, especially multi-tenant or low-trust-user setups, should treat any account with node-custom-function access as a potential root-equivalent actor until patched. The arbitrary file-read angle also exposes secrets, config files, and credentials on the host.

What defenders should watch for

  • Inventory Flowise deployments and confirm the installed version; anything ≤3.1.2 is affected.
  • Check whether ALLOW_BUILTIN_DEP=true is set in your environment — this expands exploitability to the 3.0.8–3.1.2 range.
  • Review authentication and authorization controls on /api/v1/node-custom-function — restrict who can create or edit custom function nodes.
  • Hunt for unexpected child processes spawned by the Flowise/Node.js process, particularly browser binaries (Chromium/Chrome) launched with unusual executablePath or command-line arguments.
  • Watch for outbound or local file:// requests from Puppeteer/Chromium instances, which could indicate file-exfiltration attempts.
  • If the Flowise container runs as root, consider running it as a non-root user and applying least-privilege container hardening as a compensating control pending patch deployment.

Developing intel

This write-up is based on the GitHub Security Advisory published 2026-10-07 and may be updated as more detail or confirmed exploitation emerges. Organizations running Flowise should prioritize upgrading to 3.1.3 or later. See the original advisory for full technical details: GHSA-9gvv-qjj3-2p6g.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.