Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type cve · source NVD CVE
Grouped attempts with latest status; expand for attempt history.
9 attempts · first 2026-08-18T11:17:09.993871Z · last 2026-09-04T23:19:37.577452Z
Not listed in CISA KEV (local)
Types: cisa_kev
9 attempts · first 2026-08-18T11:17:09.997969Z · last 2026-09-04T23:19:37.581517Z
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to puppeteer.launch(), which internally invokes child_process.spawn() outside the san
Types: nvd_local
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.