HIGH 8.6 NVD
CVE-2026-73484
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json,
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x58f-9m57-qc4m
- https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-pandas-methods
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-13 via NVD.
vulnfeed aggregates 10540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.