THREAT OPS › Threat News › [GHSA] GHSA-wg86-r78f-74mp (critical) — Flowise Sandbox Escape to RCE
[GHSA] GHSA-wg86-r78f-74mp (critical) — Flowise Sandbox Escape to RCE
GHSA-wg86-r78f-74mp Severity: critical CVE: CVE-2026-69253
Flowise Sandbox Escape to RCE
============================================================================= Security Advisory elttam
Topic: Flowise JavaScript Sandbox Escape
Module: Flowise
MITRE ATT&CK techniques
Indicators of compromise
- dddfb3c90eec900d747790a439bd362a764039cdsha1
- 4211bfc8f15746be4019bba557e29a7ba83d54c5sha1
- e765367fdc9761a7d9cf01a048cac15c78903b85sha1
- 0c6924bb08a2156513b447d0e600651f29ea5aa8sha1
- aff06479aa9ec24847bd65ac786b46ac85ae7e03sha1
- CVE-2026-69253cve
- CVE-2022-24785cve
- https://192.168.122.62:3000/#\url
- https://hub.docker.com/r/flowiseai/flowiseurl
- http://192.168.122.62:3000url
- http://192.168.122.62:3000/canvas/3145786c-a4c0-4989-8605-afff0c10b5beurl
- https://192.168.122.62:3000/#\\\url
- https://docs.flowiseai.com/memory#ui-and-embedded-chat\\\url
- https://docs.flowiseai.com/using-flowise/uploads#image\\\url
- admin@flowise.localemail
Original source: https://github.com/advisories/GHSA-wg86-r78f-74mp