What is CVE-2026-73487?
A regex-based Python code validator bypass vulnerability exists in Flowise before version 3.1.3. This flaw in CSV and Airtable Agent nodes allows unauthenticated attackers to inject malicious code via prompt injection, enabling dataset exfiltration through unblocked pandas functions and Server-Side Request Forgery (SSRF). Upgrading to Flowise version 3.1.3 or later is required to mitigate the issue.
Azərbaycanca: Flowise platformunda regex əsaslı Python kod doğrulama zəifliyi aşkarlanıb. Bu boşluq CSV və Airtable Agent qovşaqlarında autentifikasiya olunmamış hücumçulara prompt injection vasitəsilə zərərli kod yeritməyə, verilənlər bazasını oğurlamağa (exfiltration) və SSRF hücumları həyata keçirməyə imkan verir. Problemi aradan qaldırmaq üçün Flowise versiyasını 3.1.3 və ya daha yuxarı səviyyəyə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Flowise are affected by CVE-2026-73487?
This vulnerability exists in Flowise versions before 3.1.3.
What risks can arise if CVE-2026-73487 is exploited?
It can lead to malicious code injection via prompt injection, dataset exfiltration, and SSRF attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.