Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 03 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 14 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system. | |
| Title | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T20:18:51.372Z
Reserved: 2026-08-12T18:19:17.025Z
Link: CVE-2026-73485
Updated: 2026-08-14T18:59:25.407Z
Status : Analyzed
Published: 2026-08-13T12:17:23.807
Modified: 2026-09-03T18:51:02.733
Link: CVE-2026-73485
No data.
OpenCVE Enrichment
Updated: 2026-08-13T15:00:04Z