Executive brief
Flowise is a low-code platform that allows users to build AI applications with Airtable data integration. The AirtableAgent component executes Python code to query Airtable datasets, but fails to sanitize user input before passing it to a language model for code generation. An attacker can inject malicious prompts to trick the LLM into generating harmful Python code that executes with full system privileges, enabling remote code execution.
Technical details
This vulnerability is a prompt injection flaw in the AirtableAgent component. User input is concatenated directly into a prompt template without sanitization, then passed to an LLM (via LLMChain) to generate Python code. The LLM's output is executed unsanitized by Pyodide without any validation. An attacker can craft a prompt that breaks out of the intended data-query context and instructs the LLM to generate arbitrary Python code. The attack requires network access and the ability to send prompts to an active Flowise chatflow with AirtableAgent enabled, but no authentication is typically required for chatflow interaction. The vulnerability affects Flowise versions up to 3.0.13, with patches available in version 3.1.0 for both the flowise and flowise-components packages.
Affected products
- FlowiseAI Flowise <=3.0.13
- FlowiseAI flowise-components <=3.0.13
Timeline
- 2026-04-15: disclosed: Advisory published on GitHub
- 2026-04-16: patched: Fix released in version 3.1.0