Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.
References
| Link | Resource |
|---|---|
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x58f-9m57-qc4m | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-pandas-methods | Third Party Advisory |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x58f-9m57-qc4m | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 12:17
Updated : 2026-09-03 18:59
NVD link : CVE-2026-73484
Mitre link : CVE-2026-73484
CVE.ORG link : CVE-2026-73484
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-184
Incomplete List of Disallowed Inputs
