Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Flowise code injection vulnerabilities in Agent nodes

Flowise before version 3.1.3 contains multiple code injection vulnerabilities in the Airtable and CSV Agent nodes that allow unauthenticated attackers to execute arbitrary Python code through prompt injection and validator bypasses.

Disclosed 13 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can execute arbitrary Python code, exfiltrate datasets, perform SSRF attacks against internal services, or achieve remote code execution through the prediction API.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73485
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73487