๐Ÿ” CVE Alert

CVE-2025-34267

UNKNOWN 0.0

Flowise Authenticated Command Execution and Sandbox Bypass via Puppeteer & Playwright Packages

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier.

CWE CWE-77
Vendor flowiseai
Product flowise
Published Oct 14, 2025
Last Updated Jun 23, 2026
Stay Ahead of the Next One

Get instant alerts for flowiseai flowise

Be the first to know when new unknown vulnerabilities affecting flowiseai flowise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FlowiseAI / Flowise
3.0.1 โ‰ค 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
flowiseai.com: https://flowiseai.com/ github.com: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w github.com: https://github.com/FlowiseAI/Flowise/pull/5231 vulncheck.com: https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages

Credits

Cale Black of VulnCheck