Code Injection Vulnerability in Flowise by FlowiseAI
CVE-2026-73485
9CRITICAL
What is CVE-2026-73485?
Flowise versions prior to 3.1.3 are susceptible to a code injection vulnerability in the Airtable Agent node. This security flaw enables unauthenticated attackers to execute arbitrary Python code by circumventing the pythonCodeValidator blocklist through obfuscation techniques. By sending specially crafted prompts to a chatflow that utilizes the Airtable Agent node, attackers can inject malicious Python code, which executes within an unsandboxed Pyodide environment that offers unrestricted access to the host operating system, posing substantial risks to system integrity.
Affected Version(s)
Flowise 0 < 3.1.3
Flowise 0 < 3.1.3
Flowise 3.1.3
