CRITICAL GitHub
CVE-2026-70470
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
### Summary
The validatePythonCodeForDataFrame blacklist in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide's js module interop. This reopens the RCE paths patched as GHSA-3hjv-c53m-58jj (CSV Agent) and GHSA-v38x-c887-992f (Airtable Agent).
### Details
packages/components/src/pythonCodeValidator.ts gates every call to pyodide.runPyth
Affected Products
- npm/flowise <= 3.1.2
- npm/flowise-components <= 3.1.2
References
- https://github.com/advisories/GHSA-52fh-8v99-63c2
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-52fh-8v99-63c2
- https://github.com/FlowiseAI/Flowise/pull/6499
- https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c
This critical severity vulnerability was published on 2026-08-04 via GitHub. Affected: npm/flowise <= 3.1.2, npm/flowise-components <= 3.1.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.