S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jul 21, 2026

CVE-2026-46442 Scanner

CVE-2026-46442 Scanner - Remote Code Execution (RCE) vulnerability in Flowise

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-46442
9.4
CVSScritical
Exploitable remotely over the internet · low-privilege account sufficient.

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKEY is not configured — the common deployment case — Flowise executes this code inside a NodeVM sandbox. This sandbox can be escaped, allowing an attacker to reach the host process object and execute system commands via child_process. The result is authenticated remote code execution on the Flowise server host. This issue has been patched in version 3.1.2.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Flowiseby FlowiseAI
< 3.1.2
Updated Aug 19, 2026View on NVD →
Detail

Flowise is a drag & drop user interface used by developers and businesses to build customized large language model flows. The platform facilitates visual programming, allowing users to link various components for seamless data processing. It's commonly used in environments where machine learning models need to be trained and deployed efficiently. Developers appreciate its flexibility and ease of use, and it's often deployed in cloud environments for scalability. The software's integration capabilities make it popular for organizations looking to streamline complex processes. It can be an essential tool in the toolkit for AI research and development teams.

This vulnerability involves a remote code execution risk within the Flowise software. Unauthorized entities can exploit this flaw by submitting arbitrary JavaScript code without sufficient authorization checks. This can result in a breach of the sandbox environment, escalating the attack to the execution of arbitrary system commands. Such vulnerabilities typically arise from poor input validation and inadequate access controls. Attackers leveraging this vulnerability can execute commands with the privileges of the Flowise server host. Addressing remote code execution vulnerabilities requires ensuring strict authorization protocols and input sanitization.

The RCE vulnerability specifically affects the POST /api/v1/node-custom-function endpoint in Flowise. This endpoint fails to implement adequate route-level authorization, allowing attackers to execute JavaScript code. The issue becomes critical when E2B_APIKEY is not configured, a common deployment scenario where the software executes the code in a NodeVM sandbox. The attack can escape the sandbox context, reaching the host process and executing system commands via child_process. The consequence is full server compromise, making it a critical security risk.

If exploited, this vulnerability could allow an attacker to take complete control of the server hosting the software. The potential damage includes data theft, data manipulation, and disruption of services provided by the server. In this state, attackers can pivot to other network systems, further compromising the organization's infrastructure. It poses a severe threat to data integrity and confidentiality, potentially leading to significant financial and reputational damage.

REFERENCES

Solution Advice
  • Ensure all servers with Flowise are updated to version 3.1.2 or later.
  • Implement strict route-level authorization to verify user privileges.
  • Audit the system configuration for unnecessary exposure of the E2B_APIKEY.
  • Regularly scan the system for inconsistent or unexplained activities.
  • Enable logging and monitoring to detect unusual behavior immediately.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.