What is CVE-2026-73483?
CVE-2026-73483 is a sandbox escape vulnerability in Flowise versions <= 3.1.2 within the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated attacker can exploit the /api/v1/node-custom-function endpoint by supplying a manipulated executablePath to break out of the sandbox. Users should upgrade Flowise to the latest patched version immediately.
Azərbaycanca: CVE-2026-73483 Flowise platformasının 3.1.2 və daha əvvəlki versiyalarında vm2/@flowiseai/nodevm sandbox qaçışı (sandbox escape) zəifliyidir. Doğrulanmış istifadəçi /api/v1/node-custom-function endpoint-i vasitəsilə executablePath parametrini manipulyasiya edərək sandbox-dan çıxa bilər. Flowise istifadəçiləri dərhal ən son versiyaya yeniləmə aparmalıdır.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Flowise
FAQ2
Which versions of the Flowise platform are affected by CVE-2026-73483?
This vulnerability affects Flowise versions 3.1.2 and earlier.
Does an attacker need to be authenticated to exploit CVE-2026-73483?
Yes, an attacker must be an authenticated user to exploit this sandbox escape vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.