CVE-2026-73485 – Flowise

CVSS 8.8 IMPORTANT Zero Day – Immediate Deployment

“Multiple paths to server-side code execution make this a high-impact Flowise update.”

Flowise 3.1.3 fixes a broad set of vulnerabilities affecting agent nodes, record managers, sandbox controls, TypeORM configuration, Pyodide execution, and custom JavaScript handling. CVE-2026-69251, CVE-2026-73601, CVE-2026-69253, CVE-2026-73602, CVE-2026-73485, CVE-2026-73486, and CVE-2026-73487 each have a CVSS score of 9.0, Critical severity. CVE-2026-69256, CVE-2026-69259, CVE-2026-69264, and CVE-2026-69254 each have a CVSS score of 9.4, Critical severity. CVE-2026-69255 has a CVSS score of 9.2, Critical severity. CVE-2026-70477 and CVE-2026-70470 each have a CVSS score of 9.5, Critical severity. CVE-2026-73484 has a CVSS score of 8.6, High severity.

Several flaws provide remote code execution paths through crafted configuration, prompt injection, unsafe Python execution, sandbox escapes, and validator bypasses. Public proof-of-concept exploitation is confirmed for multiple issues in this group. Flowise 3.1.3 contains the fixes.

Key Details

Affected Product
Flowiseai Flowise
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.