Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-73487

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 58.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-73487


Contact Us

Shodan ® - All rights reserved