{"data":{"id":"c47090b7-d4d8-449d-bbf6-3b95e326be45","title":"CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated atta","summary":"Flowise before version 3.1.3 has a code injection vulnerability (a weakness that lets attackers insert malicious code) in its Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing security checks through obfuscation techniques. Attackers can send specially crafted prompts to inject malicious Python code that runs with full access to the host operating system in an unsandboxed pyodide environment (a Python runtime without security restrictions).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73485","publishedAt":"2026-08-13T12:17:23.807Z","cveId":"CVE-2026-73485","cweIds":["CWE-94"],"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Flowise","Airtable Agent"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-13T12:17:23.807Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}