CVE-2026-73487: Flowise before 3.1.3 Prompt Injection RCE via CSV Agent
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.readjson() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73487?
CVE-2026-73487 is rated with a severity score of 90.
How do I fix CVE-2026-73487?
To fix CVE-2026-73487, upgrade to Flowise version 3.1.3 or later.
What type of vulnerability is CVE-2026-73487?
CVE-2026-73487 is a prompt injection remote code execution (RCE) vulnerability due to a regex-based Python code validator bypass.
Who can be affected by CVE-2026-73487?
Unauthenticated attackers can exploit CVE-2026-73487 to execute malicious code via prompt injection.
What components of Flowise are affected by CVE-2026-73487?
CVE-2026-73487 affects the CSV and Airtable Agent nodes in Flowise versions before 3.1.3.