CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-34267

Critical · CVSS 9.9

Flowise — Authenticated RCE and Node VM sandbox escape via Puppeteer/Playwright browser binary path injection (Command Injection)

CVSS
9.9
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-77

Description

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier.

Search profile — drives PoC discovery

Symbols ALLOW_BUILTIN_DEPnodevmnode VM sandboxPuppeteerPlaywrightexecutablePathbrowser binary pathGHSA-5w3r-f6gm-c25wCVE-2025-34267CVE-2025-26319
Keywords CVE-2025-34267Flowise RCEFlowise sandbox escapeFlowise Puppeteer exploitFlowise Playwright exploitFlowise ALLOW_BUILTIN_DEPFlowise nodevm bypassFlowise authenticated RCEGHSA-5w3r-f6gm-c25w PoCFlowise browser binary path injectionFlowise tool execution RCEFlowiseAI command injection
Versions: >=3.0.1 <3.0.8

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

npm flowise 3.0.1 → 3.0.8

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z