PT-2026-34730 · Flowise · Flowise

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41138

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description Remote code execution is possible in AirtableAgent.ts due to a lack of input verification when using Pandas. User input is directly applied to the question parameter within the prompt template and reflected into the Python code without sanitization.
Recommendations Update to version 3.1.0.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41138
GHSA-F228-CHMX-V6J6

Affected Products

Flowise