Input validation error in Flowise - #VU140064

 

Input validation error in Flowise - #VU140064

Published: July 30, 2026


Vulnerability identifier: #VU140064
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and access internal network resources.

The vulnerability exists due to improper input validation in validatePythonCodeForDataFrame() used by the CSV Agent and Airtable Agent nodes when processing prompt-injection-controlled Python code from the prediction API. A remote attacker can send a specially crafted prediction request to disclose sensitive information and access internal network resources.

The issue can be reached through the unauthenticated prediction endpoint and requires a chatflow that includes a CSV Agent or Airtable Agent with loaded data.


Affected software

Flowise

Remediation

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins