people · May 20, 2026
Critical Flowise Sandbox Escape Vulnerability CVE-2026-46442 Grants Host-Level RCE
Share the canonical public link.
SecurityOnline.info published details on the Flowise sandbox escape flaw CVE-2026-46442 on May 18, 2026. The vulnerability enables remote code execution at the host level in versions prior to 3.0. Flowise is a drag-and-drop user interface for building customized large language model flows as noted in the related GitHub CVE entry CVE-2026-30824 from March 2026. Security researchers highlighted the flaw in the FlowiseAI Server package.
Below validation threshold — auto-passed without scoring