Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute malicious JavaScript files stored in the document store outside the sandbox. | |
| Title | Flowise before 3.1.3 Sandbox Escape to RCE | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-95 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T12:46:56.747Z
Reserved: 2026-08-13T11:15:12.095Z
Link: CVE-2026-73602
Updated: 2026-08-13T12:46:53.235Z
Status : Received
Published: 2026-08-13T12:17:24.480
Modified: 2026-08-13T13:19:19.073
Link: CVE-2026-73602
No data.
OpenCVE Enrichment
Updated: 2026-08-13T12:30:10Z