PT-2026-70357 · Unknown · Activepieces

CVE-2026-73083

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Activepieces versions prior to 0.80.0
Description In SANDBOX CODE ONLY mode, the engine uses the importFresh() function, which is a wrapper for Node.js require(), to load compiled user modules before the V8 isolate is applied. This allows top-level module code to bypass the sandbox and access Node.js APIs in the host engine process, such as require('child process') and fs. An authenticated user with permissions to create a Code step can exploit this to read environment secrets, including AP ENCRYPTION KEY and AP JWT SECRET, read or write files, and access internal services.
Recommendations Update to version 0.80.0.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73083
GHSA-GR3H-C2J7-R52G

Affected Products

Activepieces