Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem. | |
| Title | Flowise before 3.1.3 Sandbox Escape via Pandas Methods | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-184 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:47:27.621Z
Reserved: 2026-08-12T18:19:17.025Z
Link: CVE-2026-73484
Updated: 2026-08-13T14:47:18.452Z
Status : Received
Published: 2026-08-13T12:17:23.677
Modified: 2026-08-13T15:20:15.043
Link: CVE-2026-73484
No data.
OpenCVE Enrichment
Updated: 2026-08-13T14:30:18Z