THREAT OPS › Threat News › [GHSA] GHSA-3769-jgqc-cxm7 (critical) — Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
[GHSA] GHSA-3769-jgqc-cxm7 (critical) — Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
GHSA-3769-jgqc-cxm7 Severity: critical CVE: CVE-2026-69254
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
### Summary A sandbox escape vulnerability in `executeJavaScriptCode()` allows any authenticated user to execute arbitrary system commands as root on the Flowise server. The function accepts caller-provided `nodeVMOptions` that override the default
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-69254cve
- attacker@test.comemail
Original source: https://github.com/advisories/GHSA-3769-jgqc-cxm7