Impact
Flowise prior to version 3.1.3 contains a code injection flaw in its Airtable Agent node that allows an unauthenticated attacker to craft prompts that bypass the pythonCodeValidator blocklist using obfuscation techniques. The injected Python code runs in an unsandboxed Pyodide environment with full access to the host operating system, enabling arbitrary code execution and compromising confidentiality, integrity, and availability of the host system.
Affected Systems
The affected product is FlowiseAI’s Flowise platform. Any deployment of Flowise that uses the Airtable Agent node and runs a version older than 3.1.3 is vulnerable, including both community and enterprise installations that have not upgraded to the patched release.
Risk and Exploitability
The CVSS score of 9 indicates a critical severity, and the absence of an EPSS score means no specific exploitation probability data is available; however the public advisory suggests the flaw is widely exploitable. The vulnerability is not yet listed in the CISA KEV catalog, but the attack vector is unauthenticated remote input through the chatflow endpoint. An attacker only needs the ability to send a crafted prompt that reaches the Airtable Agent node; no credentials or privileged access are required. With its high severity and ease of exploitation, the risk to affected systems is significant.
OpenCVE Enrichment