CVE-2026-41138
CVE-2026-41138
8.8
HighPublished:
Last updated:
Source:security-advisories@github.com
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python code without any sanitization. This vulnerability is fixed in 3.1.0.
References
security-advisories@github.com
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-f228-chmx-v6j6134c704f-9b21-4f2e-91b3-4a467353bcc0
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-f228-chmx-v6j6