CVE-2026-73602

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 12:17

Updated : 2026-09-04 19:35


NVD link : CVE-2026-73602

Mitre link : CVE-2026-73602

CVE.ORG link : CVE-2026-73602


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')