PT-2026-70357 · Unknown · Activepieces
CVE-2026-73083
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Activepieces versions prior to 0.80.0
Description
In SANDBOX CODE ONLY mode, the engine uses the
importFresh() function, which is a wrapper for Node.js require(), to load compiled user modules before the V8 isolate is applied. This allows top-level module code to bypass the sandbox and access Node.js APIs in the host engine process, such as require('child process') and fs. An authenticated user with permissions to create a Code step can exploit this to read environment secrets, including AP ENCRYPTION KEY and AP JWT SECRET, read or write files, and access internal services.Recommendations
Update to version 0.80.0.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activepieces