High severity8.1NVD Advisory· Published Aug 13, 2026· Updated Sep 3, 2026
CVE-2026-73484
CVE-2026-73484
Description
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-x58f-9m57-qc4mnvdExploitVendor Advisory
- www.vulncheck.com/advisories/flowise-before-sandbox-escape-via-pandas-methodsnvdThird Party Advisory
News mentions
2- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and MoreThe Hacker News · Aug 31, 2026
- Flowise: Ten RCE and Data Exposure Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 13, 2026