PT-2026-71426 · Flowise · Flowise

·

CVE-2026-73486

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.3
Description Authenticated attackers can execute arbitrary Python code via the customReadCSV parameter in the CSV Agent node. The issue stems from a validator that relies on a static regex blocklist, which can be bypassed using obfuscation techniques. This allows for code execution within the unsandboxed pyodide environment, providing full system access.
Recommendations Update to version 3.1.3 or later. As a temporary mitigation, restrict access to the customReadCSV parameter in the CSV Agent node.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73486
GHSA-4878-CQGQ-J53V

Affected Products

Flowise