Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system.
References
| Link | Resource |
|---|---|
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c5hr-rc98-xp3g | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/flowise-before-remote-code-execution-via-airtable-agent | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 12:17
Updated : 2026-09-03 18:51
NVD link : CVE-2026-73485
Mitre link : CVE-2026-73485
CVE.ORG link : CVE-2026-73485
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
