Code Injection in Flowise CSV Agent by FlowiseAI
CVE-2026-73486
9CRITICAL
What is CVE-2026-73486?
Flowise versions prior to 3.1.3 are susceptible to a code injection vulnerability found in the CSV Agent node's customReadCSV parameter. Authenticated users can exploit this flaw to execute arbitrary Python code. The existing validator uses a static regex blocklist that can be circumvented through various obfuscation techniques, which allows attackers to run code in the unsandboxed pyodide environment, potentially compromising the system's integrity and security.
Affected Version(s)
Flowise 0 < 3.1.3
Flowise 0 < 3.1.3
Flowise 3.1.3
