CRITICAL 9.0 NVD
CVE-2026-73486
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbi
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access.
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4878-cqgq-j53v
- https://www.vulncheck.com/advisories/flowise-before-code-injection-via-csv-agent-customrea
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4878-cqgq-j53v
This critical severity vulnerability with a CVSS score of 9.0 was published on 2026-08-13 via NVD.
Risk Timeline
CVE Disclosed2026-08-13 · -1 days ago
Remediation Resources
vulnfeed aggregates 10540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.