Prompt Injection Vulnerability in Flowise by FlowiseAI
CVE-2026-73487

9CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73487?

Flowise versions prior to 3.1.3 are susceptible to a regex-based Python code validator bypass. This flaw enables unauthenticated attackers to perform prompt injection attacks through CSV and Airtable Agent nodes. By leveraging unblocked pandas functions such as pd.read_json(), malicious actors can exfiltrate datasets, conduct Server-Side Request Forgery (SSRF) against internal services, or execute arbitrary code via the unauthenticated prediction API, posing significant risks to data integrity and application security.

Affected Version(s)

Flowise 0 < 3.1.3

Flowise 0 < 3.1.3

Flowise 3.1.3

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

p80n-sec
.