What is CVE-2026-73485?
Flowise versions before 3.1.3 contain a code injection vulnerability in the Airtable Agent node. This allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist using obfuscation techniques. Users should immediately upgrade to version 3.1.3 or later.
Azərbaycanca: Flowise versiya 3.1.3-dən əvvəlki versiyalarda Airtable Agent node-da kod inyeksiyası zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış hücumçulara pythonCodeValidator blok siyahısını obfuskasiya üsulları ilə keçərək ixtiyari Python kodu icra etməyə imkan verir. Flowise istifadəçiləri dərhal 3.1.3 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: Flowise
FAQ2
Which versions of Flowise are affected by CVE-2026-73485?
Flowise versions before 3.1.3 are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-73485?
An unauthenticated attacker can execute arbitrary Python code by bypassing the pythonCodeValidator blocklist using obfuscation techniques.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.