What is CVE-2026-73484?
CVE-2026-73484 is a sandbox escape vulnerability in Flowise versions before 3.1.3 within pythonCodeValidator.ts. It fails to block native Pandas DataFrame methods like to_csv and to_json, allowing authenticated attackers to exfiltrate uploaded CSV data or write arbitrary files to the server. Update Flowise to version 3.1.3 or later to mitigate this issue.
Azərbaycanca: CVE-2026-73484 Flowise 3.1.3-dən əvvəlki versiyalarda pythonCodeValidator.ts-də qum qutusundan qaçma zəifliyidir. O, Pandas DataFrame-in to_csv, to_json kimi təhlükəli metodlarını bloklaya bilmir, autentifikasiya olunmuş hücumçulara yüklənmiş CSV məlumatlarını sızdırmağa və ya serverə ixtiyari fayllar yazmağa imkan verir. Flowise-i 3.1.3 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Flowise are affected by CVE-2026-73484?
Flowise versions before 3.1.3 are affected by this vulnerability.
What does CVE-2026-73484 allow authenticated attackers to do?
This vulnerability allows authenticated attackers to exfiltrate uploaded CSV data or write arbitrary files to the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.