What is CVE-2026-73602?
This vulnerability is a sandbox escape in the vm2 JavaScript sandbox within Flowise versions prior to 3.1.3. Authenticated users can execute arbitrary code by bypassing moment locale validation via a crafted fake String object with a malicious match function. Immediate upgrade to version 3.1.3 or later is required.
Azərbaycanca: Bu boşluq Flowise platformasının 3.1.3-dən əvvəlki versiyalarında vm2 JavaScript sandbox-un escape (sərhəddən çıxma) zəifliyidir. Doğrulanmış istifadəçilər moment locale yoxlamasını keçərək xüsusi hazırlanmış String obyekti ilə ixtiyari kod icra edə bilərlər. Dərhal 3.1.3 və ya yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Flowise are affected by CVE-2026-73602?
This vulnerability affects Flowise versions prior to 3.1.3.
What privilege is required for a user to exploit CVE-2026-73602 for arbitrary code execution?
An attacker must be an authenticated user to exploit this vulnerability for arbitrary code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.