CVE-2026-70470 | FlowiseAI Flowise up to 3.1.2 Python Code Validator pythonCodeValidator.ts validatePythonCodeForDataFrame os command injection

SecurityVulns

A vulnerability was found in FlowiseAI Flowise up to 3.1.2 and classified as critical. Affected by this issue is the function validatePythonCodeForDataFrame of the file packages/components/src/pythonCodeValidator.ts of the component Python Code Validator. The manipulation results in os command injection.

This vulnerability is cataloged as CVE-2026-70470. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More