Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API.
References
| Link | Resource |
|---|---|
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-w7x8-q2gp-5cgg | Exploit Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/flowise-before-prompt-injection-rce-via-csv-agent | Third Party Advisory |
| https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-w7x8-q2gp-5cgg | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 12:17
Updated : 2026-09-03 18:42
NVD link : CVE-2026-73487
Mitre link : CVE-2026-73487
CVE.ORG link : CVE-2026-73487
JSON object : View
Products Affected
flowiseai
- flowise
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
