GitHub Security Advisory (GHSA-x58f-9m57-qc4m)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x58f-9m57-qc4m CVE-2026-73484
HIGH
Flowise before 3.1.3 Sandbox Escape via Pandas Methods
Record summary
CVE-2026-73484 has a selected CVSS score of 8.6 (high).
Description
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.3 | affected |
| 3.1.3 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73484 VulnCheck Advisory: Flowise before 3.1.3 Sandbox Escape via Pandas MethodsThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-pandas-methods