Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability…

cve CVE-2025-34267 1 source, 1 claim · Watch

NVD writes:
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in exe… the claim
Severity
CRITICAL NVD
CVSS
9.9 NVD
Vendor
FlowiseAI NVD
Product
Flowise NVD
CWE
CWE-77 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2025-10-14first spoke of it: Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier.NVD

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier.

What it is to other things

affectsflowiseai/flowise
NVD
made_byflowiseai
NVD
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCno
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD9.9
receipt
Source
NVD
Its words
9.9
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4
cvss4
NVD8.4
receipt
Source
NVD
Its words
8.4
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTC8.4
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-77
receipt
Source
NVD
Its words
CWE-77
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCWE-77
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDpoc
A public proof of concept exists, or exploitation is trivial.
receipt
Source
NVD
Its words
poc
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCpoc
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDFlowise
receipt
Source
NVD
Its words
Flowise
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDCRITICAL
From the CVSS base score at 9.0 and above.
receipt
Source
NVD
Its words
CRITICAL
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCRITICAL
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
critical
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCpartial
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDFlowiseAI
receipt
Source
NVD
Its words
FlowiseAI
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "nodevm-based tool execution harness"
            ],
            "packageURL": "pkg:github/FlowiseAI/Flowise",
            "product": "Flowise",
            "repo": "https://github.com/FlowiseAI/Flowise",
            "vendor": "FlowiseAI",
            "versions": [
              {
                "lessThanOrEqual": "3.0.8",
                "status": "affected",
                "version": "3.0.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D55061AC-1335-49A7-9E2D-448EE268DB95",
                "versionEndExcluding": "3.0.8",
                "versionStartIncluding": "3.0.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier."
      },
      {
        "lang": "es",
        "value": "Flowise v3.0.1 menor que 3.0.8 y todas las versiones posteriores con 'ALLOW_BUILTIN_DEP' habilitado contienen una vulnerabilidad de ejecución remota de código autenticada y un escape de sandbox de la VM de Node debido al uso inseguro de módulos integrados (Puppeteer y Playwright) dentro del entorno de ejecución de nodevm. Un atacante autenticado capaz de crear o ejecutar una herramienta que aproveche Puppeteer/Playwright puede especificar rutas binarias y parámetros del navegador controlados por el atacante. Cuando la herramienta se ejecuta, el ejecutable/los parámetros controlados por el atacante se ejecutan en el host y eluden las restricciones de sandbox de nodevm previstas, lo que resulta en la ejecución de código arbitrario en el contexto del host. Esta vulnerabilidad fue asignada incorrectamente como un duplicado de CVE-2025-26319 por los desarrolladores y debe considerarse distinta de ese identificador."
      }
    ],
    "id": "CVE-2025-34267",
    "lastModified": "2026-10-05T15:10:00.590",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.0,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "LOW",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34267",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-14T20:32:58.710614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-14T20:15:34.147",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Product"
        ],
        "url": "https://flowiseai.com/"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/pull/5231"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5w3r-f6gm-c25w"
      },
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://www.vulncheck.com/advisories/flowise-auth-command-execution-and-sandbox-bypass-via-puppeteer-and-playwright-packages"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-77"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier.
zetlyn/cve-nvd · 2025-10-14
automatable no cvss 9.9 cvss4 8.4 cvss4_vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H cwe CWE-77 exploitation poc product Flowise severity CRITICAL status Analyzed technical_impact partial vendor FlowiseAI source