Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-73486

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 25.4%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-73486


Contact Us

Shodan ® - All rights reserved