Impact
Flowise before version 3.1.3 contains a sandbox escape flaw in the vm2 JavaScript sandbox that can be triggered by authenticated users. By exploiting a loophole in the moment locale validation, an attacker can craft a malicious String object whose match function bypasses path‑traversal checks, allowing execution of arbitrary JavaScript files stored outside the sandbox. The vulnerability is identified as CWE‑95 and results in untrusted code running with the privileges of the application process. The impact is full compromise of confidentiality, integrity, and availability for the affected instance.
Affected Systems
The affected product is FlowiseAI Flowise and all releases prior to 3.1.3. Users running versions 3.1.2 or earlier are vulnerable if they allow authenticated access to the sandboxed execution paths.
Risk and Exploitability
The CVSS score of 9 indicates a high severity level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is restricted to authenticated users, meaning internal or compromised accounts can leverage the flaw. If exploited, the attacker could execute arbitrary code on the host, compromising the entire infrastructure. The lack of public exploitation data means the risk remains theoretical, but the high severity and required authentication make remediation a priority.
OpenCVE Enrichment