CVE-2026-73486 | FlowiseAI Flowise up to 3.1.2 CSV Agent node customReadCSV code injection

SecurityVulns

A vulnerability categorized as critical has been discovered in FlowiseAI Flowise up to 3.1.2. This impacts an unknown function of the component CSV Agent node. The manipulation of the argument customReadCSV results in code injection.

This vulnerability is identified as CVE-2026-73486. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More