CVE-2026-73484Patch(flowiseai / flowise)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CCB Alert@CCBalert
    Patch

    Warning: #Flowise patched multiple critical vulnerabilities including the critical #CVE-2026-73484. To learn more about #RCE, sandbox escape, information disclosure, other vulnerabilities and their #PoCs, read the official Security Advisories at: https://github.com/FlowiseAI/Flowise/security/advisories?page=2 #Patch

    Post summary

    Flowise has released a patch for the critical CVE‑2026‑73484 and related vulnerabilities, with PoCs and mitigation details available in their official security advisories.

    01000317
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more