Flowise CSV/Airtable Agent Validator Bypass Enables Prompt-Injection-Driven Data Exfiltration and SSRF (CVE-2026-73487)
A newly published GitHub Security Advisory (GHSA-w7x8-q2gp-5cgg, CVE-2026-73487) discloses a critical flaw in Flowise's CSV Agent and Airtable Agent nodes, affecting versions up to and including 3.1.2. According to the advisory, these nodes sanitize LLM-generated Python code with a regex-based blocklist (validatePythonCodeForDataFrame()) before executing it in a Pyodide sandbox. The reported bypasses are structural: pandas functions that fetch remote data — pd.read_json(), pd.read_csv(), pd.read_html(), pd.read_fwf() — are never checked by the blocklist, and a word-boundary regex error means importlib slips past the import filter. The advisory states these bypasses are reachable via the unauthenticated prediction API through prompt injection, and documents working proof-of-concept requests for data exfiltration and SSRF (including a request to the AWS metadata endpoint). It is explicitly described as a distinct vulnerability class from the earlier, already-patched GHSA-3hjv-c53m-58jj (ZDI-CAN-29411).
Why It Matters
CSV Agent and Airtable Agent chatflows are common patterns for teams building data-analysis assistants on Flowise, and the advisory notes the prediction endpoint requires no API key by default. If accurate, any externally reachable chatflow using these nodes could allow an attacker to exfiltrate the entirety of a loaded dataset, probe internal network services, or reach cloud metadata endpoints — all without authentication, simply by crafting a prompt-injection payload in the question field. The advisory also flags that the underlying design (a regex blocklist guarding code execution) is structurally fragile, meaning further bypasses beyond those already published should be expected until the validator is replaced with an allowlist/AST-based approach.
What Defenders Should Watch For
- Inventory any self-hosted Flowise deployments (version ≤ 3.1.2) and identify chatflows using the CSV Agent or Airtable Agent nodes.
- Check whether prediction endpoints are exposed without authentication/API keys, and restrict or gate access if so.
- Hunt for outbound HTTP requests from the Flowise host to unfamiliar external domains or to internal/metadata IP ranges (e.g., 169.254.169.254) originating from the application process or its Pyodide/worker runtime.
- Review egress controls — the advisory's own remediation guidance calls for running the Pyodide execution environment without outbound network access as a mitigation.
- Treat any user- or LLM-generated Python passed to a pandas/numpy execution context as untrusted until the vendor ships an AST-based allowlist fix; blocklist patches are described as incomplete.
- Watch for a vendor patch/advisory update and apply it promptly given the unauthenticated, low-complexity attack path described.
Developing Intel
This is a same-day advisory and details may evolve as the vendor responds; this post reflects only what has been reported so far and should not be treated as a final determination of exploitation in the wild. For full technical detail, proof-of-concept code, and remediation guidance, see the original advisory: GHSA-w7x8-q2gp-5cgg.