THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3769-jgqc-cxm7 (critical) — Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

[GHSA] GHSA-3769-jgqc-cxm7 (critical) — Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

medgithub_advisoriesPublished 2026-08-04

GHSA-3769-jgqc-cxm7 Severity: critical CVE: CVE-2026-69254

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

### Summary A sandbox escape vulnerability in `executeJavaScriptCode()` allows any authenticated user to execute arbitrary system commands as root on the Flowise server. The function accepts caller-provided `nodeVMOptions` that override the default

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3769-jgqc-cxm7