Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading
Published Aug 11, 2026
7.6
HIGHCVSS 4.0
EPSS 0.25%
Description
Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js require(), before the V8 isolate is applied. Top-level module code can therefore call require('child_process'), access fs, and use other Node.js APIs in the host engine process outside the sandbox. An authenticated user who can create a Code step can read environment secrets including AP_ENCRYPTION_KEY and AP_JWT_SECRET, read or write files, and reach internal services. This issue is fixed in version 0.80.0.
Affected products
-
- Version < 0.80.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Activepieces | Activepieces | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56551 Advisory
- https://github.com/activepieces/activepieces/releases/tag/0.80.0 x_refsource_MISC
- https://github.com/activepieces/activepieces/security/advisories/GHSA-gr3h-c2j7-r52g x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56551 | Advisory | |
| https://github.com/activepieces/activepieces/releases/tag/0.80.0 | x_refsource_MISC | |
| https://github.com/activepieces/activepieces/security/advisories/GHSA-gr3h-c2j7-r52g | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.