Flowise before 3.1.3 contains a regex-based Python code...
Critical severity
Unreviewed
Published
Aug 13, 2026
to the GitHub Advisory Database
•
Updated Aug 13, 2026
Description
Published by the National Vulnerability Database
Aug 13, 2026
Published to the GitHub Advisory Database
Aug 13, 2026
Last updated
Aug 13, 2026
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API.
References