GitHub Security Advisory (GHSA-c5hr-rc98-xp3g)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c5hr-rc98-xp3g CVE-2026-73485
CRITICAL
Flowise before 3.1.3 Remote Code Execution via Airtable Agent
Record summary
CVE-2026-73485 has a selected CVSS score of 9.0 (critical).
Description
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.3 | affected |
| 3.1.3 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73485 VulnCheck Advisory: Flowise before 3.1.3 Remote Code Execution via Airtable AgentThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-remote-code-execution-via-airtable-agent