CVE-2026-73484: Flowise before 3.1.3 Sandbox Escape via Pandas Methods
Published Aug 13, 2026
·Updated
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like tocsv, tojson, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.
Affected Software
1 affected component
Flowise<3.1.3
Event History
Aug 13, 2026
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73484?
The severity of CVE-2026-73484 is rated at risk level 58.
2
How do I fix CVE-2026-73484?
To fix CVE-2026-73484, upgrade Flowise to version 3.1.3 or later.
3
What type of vulnerability is CVE-2026-73484?
CVE-2026-73484 is a sandbox escape vulnerability impacting Flowise.
4
What can attackers do by exploiting CVE-2026-73484?
Authenticated attackers can exfiltrate CSV data or write arbitrary files to the server filesystem.
5
In which component of Flowise does CVE-2026-73484 occur?
CVE-2026-73484 occurs in the pythonCodeValidator.ts component of Flowise.