Junglewise Threat Intelligence

CVE-2026-41138: Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.

CVE-2026-41138 · Severity: high · CVSS 8.3 · Published 2026-04-16

Technologies: FlowiseAI Flowise, flowise (npm), flowise-components (npm). Vendors: FlowiseAI, npm.

Executive brief

Flowise is a low-code platform that allows users to build AI applications with Airtable data integration. The AirtableAgent component executes Python code to query Airtable datasets, but fails to sanitize user input before passing it to a language model for code generation. An attacker can inject malicious prompts to trick the LLM into generating harmful Python code that executes with full system privileges, enabling remote code execution.

Technical details

This vulnerability is a prompt injection flaw in the AirtableAgent component. User input is concatenated directly into a prompt template without sanitization, then passed to an LLM (via LLMChain) to generate Python code. The LLM's output is executed unsanitized by Pyodide without any validation. An attacker can craft a prompt that breaks out of the intended data-query context and instructs the LLM to generate arbitrary Python code. The attack requires network access and the ability to send prompts to an active Flowise chatflow with AirtableAgent enabled, but no authentication is typically required for chatflow interaction. The vulnerability affects Flowise versions up to 3.0.13, with patches available in version 3.1.0 for both the flowise and flowise-components packages.

Affected products

  • FlowiseAI Flowise <=3.0.13
  • FlowiseAI flowise-components <=3.0.13

Timeline

  • 2026-04-15: disclosed: Advisory published on GitHub
  • 2026-04-16: patched: Fix released in version 3.1.0

References

Related threats