{"id":"GHSA-x3jw-7gj7-qv6m","title":"Duplicate Advisory: Flowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass","summary":"Duplicate Advisory: Flowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass","severity":"critical","cvss":9.8,"cwe":["CWE-94"],"vendor":"flowise","product":"flowise","ecosystem":"pip","affected":["flowise < 3.1.3"],"patched":["flowise 3.1.3"],"published":"2026-08-13","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:17:06Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-x3jw-7gj7-qv6m","references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-w7x8-q2gp-5cgg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73487"},{"url":"https://www.vulncheck.com/advisories/flowise-before-prompt-injection-rce-via-csv-agent"},{"url":"https://github.com/advisories/GHSA-x3jw-7gj7-qv6m"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-07T16:38:22.233Z","slug":"GHSA-x3jw-7gj7-qv6m","body":"## Overview\n\n# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-w7x8-q2gp-5cgg. This link is maintained to preserve external references.\n\n# Original Description\n\nFlowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API.\n\n## Affected packages\n\n- `flowise < 3.1.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `flowise 3.1.3`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}