CVE-2026-46442Disclosure(flowiseai / flowise)

LOWCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for flowiseai flowise systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is not configured — the common deployment case — Flowise executes this code inside a NodeVM sandbox. This sandbox can be escaped, allowing an attacker to reach the host process object and execute system commands via child_process. The result is authenticated remote code execution on the Flowise server host. This issue has been patched in version 3.1.2.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-15); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-15: 1Mentions · 2026-05-19: 1Mentions · 2026-07-17: 1Mentions · 2026-07-21: 1Active Exploitation · 2026-07-17: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-21: 105-1505-1907-1707-21
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-151
Disclosure1
2026-05-191
Disclosure1
2026-07-171
Active Exploitation1
2026-07-211
Disclosure1
Full discourse4 posts
  • KEVIntel@kev_intel
    Active Exploitation

    CVE-2026-46442 is hitting KEVIntel’s Flowise sensor. First seen July 13, with attempts increasing: 20 from 7 attacker IPs. The odd part? It’s an authenticated RCE, but attackers are running the exploit unauthenticated. Now in our KEV Feed: https://kevintel.com/CVE-2026-46442 https://t.co/B5A9Nc6SoL

    Post summary

    CVE-2026-46442 is an authenticated RCE in KEVIntel’s Flowise sensor that is actively being exploited in the wild with multiple attackers.

    03071797
    61 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-46442 - critical 🚨 Flowise < 3.1.2 - node-custom-function Unauthorized RCE > Flowise is a drag & drop user interface to build a customized large language model fl... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-46442 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-46442 exposes an unauthorized RCE in Flowise versions below 3.1.2 through a node‑custom‑function, with no PoC, exploit code, or mitigation details provided.

    01035417
    1.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - FlowiseAI Authenticated RCE via Custom JS Function & NodeVM Sandbox Escape (CVE-2026-46442) The endpoint POST /api/v1/node-custom-function lacks proper authorization, allowing any authenticated user (or holder of a valid API key) to submit arbitrary JavaScript. When E2B_APIKEY is not set (the default for most deployments), the code runs in a vulnerable NodeVM sandbox that can be escaped to reach the host process and execute arbitrary system commands via child_process. This results in Critical authenticated remote code execution on the Flowise server. 👉Affected: flowise <= 3.1.1

    Post summary

    A newly disclosed critical authenticated RCE in FlowiseAI allows arbitrary JavaScript execution via a sandbox escape, but no exploit code, patch, or active exploitation evidence is provided.

    0002089
    196 followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    CVE-2026-46442 in Flowise allows authenticated users to escape the NodeVM sandbox and execute system commands. Secure your AI infrastructure now! #Flowise #AISecurity #GenerativeAI #CyberSecurity #InfoSec #RCE #SandboxEscape #CVE https://securityonline.info/flowise-sandbox-escape-vulnerability-cve-2026-46442-host-rce https://t.co/AnMXMW45OB

    Post summary

    The tweet announces CVE‑2026‑46442, a sandbox escape in Flowise that allows authenticated users to execute system commands, but it provides no proof‑of‑concept, active exploitation evidence, or patch information.

    00001290
    12.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more