GHSA-x3jw-7gj7-qv6mCritical· 9.8▾ MidnightDuplicate Advisory: Flowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-w7x8-q2gp-5cgg. This link is maintained to preserve external references.
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API.
flowise < 3.1.3Upgrade to a patched release:
flowise 3.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73487CriticalFlowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
GHSA-5w6g-rc45-wvv9Critical· 9.8Duplicate Advisory: Flowise OverrideConfig security vulnerability
CVE-2026-52098Critical· 9.8An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint
CVE-2026-70477Critical· 9.8Flowise is a drag & drop user interface to build a customized large language model flow
CVE-2026-69264Critical· 9.8Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide
CVE-2026-69255High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow