Eval Injection in Flowise - #VU140074

 

Eval Injection in Flowise - #VU140074

Published: July 30, 2026


Vulnerability identifier: #VU140074
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the vm2-based JavaScript sandbox used by the custom function agent flow node and custom tool when executing user-supplied JavaScript. A remote user can submit crafted JavaScript that escapes the sandbox to execute arbitrary code.

Exploitation requires authentication and affects instances using the default vm2 sandbox.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins