๐Ÿ” CVE Alert

CVE-2026-73486

UNKNOWN 0.0

Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access.

CWE CWE-94
Vendor flowiseai
Product flowise
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for flowiseai flowise

Be the first to know when new unknown vulnerabilities affecting flowiseai flowise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FlowiseAI / Flowise
0 < 3.1.3
FlowiseAI / Flowise
0 < 3.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4878-cqgq-j53v vulncheck.com: https://www.vulncheck.com/advisories/flowise-before-code-injection-via-csv-agent-customreadcsv

Credits

๐Ÿ” zdi-disclosures