Critical severity9.9NVD Advisory· Published Aug 13, 2026· Updated Sep 4, 2026
CVE-2026-73602
CVE-2026-73602
Description
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/FlowiseAI/Flowise/security/advisories/GHSA-rqh4-rxw3-93rpnvdExploitVendor Advisory
- www.vulncheck.com/advisories/flowise-before-sandbox-escape-to-rcenvdThird Party Advisory
- github.com/FlowiseAI/Flowise/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5nvdBroken Link
News mentions
2- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- Flowise: Ten RCE and Data Exposure Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 13, 2026