CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69254

criticalcovered by 2 sourcesfirst seen 2026-08-04
Summary A sandbox escape vulnerability in executeJavaScriptCode() allows any authenticated user to execute arbitrary system commands as root on the Flowise server. The function accepts caller-provided nodeVMOptions that override the default sandbox security settings via JavaScript's spread operator, allowing an attacker to re-enable blocked modules like child_process and fs. Details The vulnerability is in packages/components/src/utils.ts at line 1755: const finalNodeVMOptions = { ...defaultNodeVMOptions, ...nodeVMOptions } The executeJavaScriptCode() function (line 1569) creates a NodeVM sandbox with secure defaults that restrict which Node.js built-in modules can be required: async (code, sandbox, options = {}) => { const { nodeVMOptions = {} } = options; // ... const defaultNodeVMOptions = { require: { builtin: builtinDeps, // restricted allowlist — blocks child_process, fs, os, etc. mock: secureWrappers }, eval: false, wasm: false } const finalNodeVMOptions = { ...defaultNodeVMOptions, ...nodeVMOptions } // ← VULN: caller overrides security settings const vm = new NodeVM(finalNodeVMOptions) } The spread operator allows any caller to override require.builtin with ["*"], which permits all Node.js built-in modules including child_process. Taint 01: Route Registration packages/server/src/routes/node-custom-functions/index.ts (line 8) Taint 02: Controller executeCustomFunction() passes req.body to service — packages/server/src/controllers/nodes/index.ts (line 90) Taint 03: Service executeCustomNodeFunction() loads the customFunction node and calls init() with user-provided javascriptFunction — packages/server/src/utils/executeCustomNodeFunction.ts (line 49) Taint 04: Sandbox Entry Code runs inside NodeVM via executeJavaScriptCode() — packages/components/src/utils.ts (line 1760) Taint 05: Escape Inside the sandbox, the attacker requires flowise-components/dist/src/utils.js by absolute path (bypassing the module allowlist), obtaining a reference to executeJav

⚡ Watch CVE-2026-69254

Get an email if CVE-2026-69254 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-69254

CVE.org record

Embed the live status

CVE-2026-69254 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69254 status](https://www.csirts.com/badge/CVE-2026-69254)](https://www.csirts.com/cve/CVE-2026-69254)