{"data":{"id":"89215702-e795-41b5-b522-ae8937becf80","title":"GHSA-52fh-8v99-63c2: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE","summary":"# Summary\n\nFlowise, a platform that uses Pyodide (Python running in the browser), has a security vulnerability where its Python code validator can be bypassed using Unicode homoglyphs (visually similar characters). An attacker can craft malicious Python code with characters like \"𝐚\" (mathematical bold a) that look like regular letters but bypass the blacklist, allowing them to execute arbitrary Python and OS commands on the Flowise server through Pyodide's JavaScript interop. This re-introduces","solution":"N/A — no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-52fh-8v99-63c2","publishedAt":"2026-08-04T17:31:09.000Z","cveId":"CVE-2026-70470","cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["rag_poisoning"],"issueType":"vulnerability","affectedPackages":["flowise-components@<= 3.1.2 (fixed: 3.1.3)","flowise@<= 3.1.2 (fixed: 3.1.3)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["Flowise","Pyodide"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-04T17:31:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}