Executive brief
Flowise is an open-source low-code platform for building conversational AI applications. The Airtable Agent node allows users to query Airtable data through a chatbot interface. A vulnerability in this node allows unauthenticated attackers to inject and execute arbitrary Python code by crafting malicious prompts, leading to full remote code execution on the server with the privileges of the running process.
Technical details
This is a code injection vulnerability (CWE-94) in the Airtable Agent's run method. The vulnerability exists because LLM-generated Python code is validated using a regex-based blocklist (pythonCodeValidator) before execution in pyodide, but the blocklist can be bypassed through multiple obfuscation techniques including string concatenation, chr() encoding, decorator syntax, and frame inspection. Additionally, pyodide is not sandboxed and has full access to OS interfaces. Unauthenticated attackers can exploit this by sending crafted prompts that cause the LLM to generate obfuscated malicious Python code, while authenticated attackers can configure malicious Airtable tables or servers. No authentication is required for exploitation via prompt injection.
Affected products
- Flowise Flowise before 3.1.3
Timeline
- 2026-07-29: disclosed: GitHub Security Advisory GHSA-c5hr-rc98-xp3g published
- 2026-08-13: advisory: CVE-2026-73485 published on NVD
- 2026-08-13: patched: Version 3.1.3 released with patch