What is CVE-2026-73486?
CVE-2026-73486 is a code injection vulnerability in the CSV Agent node's customReadCSV parameter in Flowise versions before 3.1.3. Authenticated attackers can bypass the static regex blocklist via obfuscation techniques to execute arbitrary Python code. Upgrading to version 3.1.3 or later is strongly recommended.
Azərbaycanca: CVE-2026-73486, Flowise platformunun 3.1.3-dən əvvəlki versiyalarında CSV Agent node-unun customReadCSV parametrində aşkar edilmiş kod inyeksiya zəifliyidir. Autentifikasiya olunmuş hücumçu, validatorun statik regex bloklama siyahısını müəyyən obfuscation texnikaları ilə keçərək ixtiyari Python kodu icra edə bilər. Təsirlənən sistemlərin dərhal 3.1.3 və ya daha yeni versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Does exploiting CVE-2026-73486 require the attacker to be authenticated?
Yes, this vulnerability can only be exploited by an authenticated attacker.
Which version should be upgraded to in order to fix CVE-2026-73486?
It is recommended to upgrade affected systems to version 3.1.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.