Flowise CSV and Airtable Agent Python Validator Bypass
Flowise versions <= 3.1.2 are vulnerable to data exfiltration and SSRF via a flawed regex-based Python validator that fails to restrict pre-imported pandas and numpy methods.
What's new
- 1. added detection rule: Detect Exploitation of CVE-2026-73483 in Flowise Oct 7, 16:56 via ghsa
Flowise versions 3.1.2 and earlier contain a critical security vulnerability in the CSV and Airtable agent nodes. These nodes utilize a structurally insufficient regex-based blocklist (validatePythonCodeForDataFrame()) to sanitize LLM-generated Python code before execution in a Pyodide (WebAssembly) environment. The blocklist approach fails because the executor pre-imports pandas and numpy, exposing broad API surfaces that accept network-capable functions (e.g., pd.read_json, pd.read_csv, pd.read_html) which are not filtered.
Attackers can leverage prompt injection via the unauthenticated prediction API to force the LLM to generate bypass code. This code executes in the Flowise backend, allowing attackers to exfiltrate dataset contents, conduct SSRF against internal services or cloud metadata endpoints, and attempt to load native libraries using np.ctypeslib. This finding persists despite previous patches in version 3.1.0 that addressed different import aliasing techniques, highlighting the fundamental insecurity of using regex blocklists for code execution validation.
Attack Chain
- Attacker identifies a Flowise instance exposing a CSV Agent or Airtable Agent chatflow endpoint.
- Attacker sends a POST request to the unauthenticated
/api/v1/prediction/:idendpoint containing a malicious prompt injection payload. - The LLM processes the prompt and is steered to generate Python code leveraging unrestricted pandas functions like
pd.read_json(). - The Flowise
validatePythonCodeForDataFrame()function scans the generated code against the 38-pattern regex blocklist. - The validator fails to trigger because the functions used (e.g.,
pd.read_json) are not in the blocklist and no forbidden keywords likeimportare utilized. - The Pyodide runtime executes the generated code, prepended with pre-imported
pandasandnumpylibraries. - The
pd.read_json()function makes an outbound HTTP request to an attacker-controlled server containing the serialized CSV dataset or sensitive cloud metadata obtained via SSRF. - The attacker receives the sensitive data via their listener, completing the exfiltration.
Impact
Successful exploitation allows unauthenticated attackers to steal sensitive data loaded into CSV or Airtable agents, access cloud metadata services (e.g., 169.254.169.254), and perform internal network reconnaissance. Because the vulnerability is reachable via the default prediction API without authentication, it poses a high risk to any deployment where these agents are active.
Recommendation
- Implement an AST-based allowlist for Python code execution instead of relying on regex blocklists.
- Block all pandas and numpy functions capable of network I/O, such as
pd.read_json,pd.read_csv,pd.read_html, andpd.read_fwf. - Restrict access to the
/api/v1/prediction/endpoint by enforcing authentication. - Monitor web server logs for high-frequency or suspicious POST requests to the prediction endpoint containing Python-like syntax in the
questionfield.
Immediate actions
Audit all Flowise deployments for exposure to the prediction API.
Mitigations
Restrict access to the /api/v1/prediction/ endpoint to authenticated users only.
All Flowise nodes
Detection coverage 2
Detect Suspicious Flowise Prediction API Payloads
highDetects potential prompt injection attempts against the Flowise prediction API containing Python code patterns used to bypass the validator.
Detect Exploitation of CVE-2026-73483 in Flowise
highDetects potential exploitation attempts of the node-custom-function endpoint by monitoring for requests containing puppeteer configuration parameters like executablePath.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
1
url
| Type | Value |
|---|---|
| url | http://169.254.169.254/latest/meta-data/ |