CVE-2026-73483 | FlowiseAI Flowise up to 3.1.2 JavaScript Sandbox node-custom-function child_process.spawn executablePath/args os command injection

SecurityVulns

A vulnerability identified as very critical has been detected in FlowiseAI Flowise up to 3.1.2. Affected is the function child_process.spawn of the file /api/v1/node-custom-function of the component JavaScript Sandbox. This manipulation of the argument executablePath/args causes os command injection.

This vulnerability is tracked as CVE-2026-73483. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More