GitHub Security Advisory (GHSA-4878-cqgq-j53v)Vendor advisory
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4878-cqgq-j53v CVE-2026-73486
CRITICAL
Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV
Record summary
CVE-2026-73486 has a selected CVSS score of 9.0 (critical).
Description
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlowiseBrowse FlowiseAI / FlowiseDefault status: unaffected | CVE List | Before 3.1.3 | affected |
| 3.1.3 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-73486 VulnCheck Advisory: Flowise before 3.1.3 Code Injection via CSV Agent customReadCSVThird-party advisory
https://www.vulncheck.com/advisories/flowise-before-code-injection-via-csv-agent-customreadcsv