Summary
CVE-2026-70470 is a critical remote code execution vulnerability in Flowise (FlowiseAI), the open-source low-code platform for building LLM apps and AI agents. Flowise’s Python code validator can be bypassed with Unicode homoglyph characters, allowing arbitrary Python execution in Pyodide and OS command execution on the host. It carries a CVSS 4.0 base score of 9.5 (Critical).
Technical details
- Root cause: The Python code validator relies on a JavaScript regex blacklist (CWE-184, Incomplete List of Disallowed Inputs). JavaScript’s
bword boundary only recognizes ASCII characters, so a homoglyph such as__cl𝐚ss__(using U+1D41A, "Mathematical bold small a") is not caught by patterns likeb__class__b. - Trigger conditions: Python 3 applies NFKC normalization to identifiers at parse time, converting the homoglyph back to its ASCII form during execution. The mismatch lets forbidden identifiers slip past the blacklist and run inside Pyodide, reaching OS command execution.
- Attack vector: Network. Users who can reach a chatflow — including unauthenticated users on public CSV Agent or Airtable Agent chatflows — can inject the malicious Python via LLM-generated responses or
customReadCSVconfiguration parameters. - Impact: Arbitrary OS command execution as the Flowise process on the host, enabling credential theft, file access, network pivoting, and multi-tenant workspace compromise.
Affected software
- Flowise (npm
flowiseandflowise-components) versions ≤ 3.1.2.
Severity
- CVSS 4.0 base score: 9.5 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Mitigation and recommended actions
- Immediate: Upgrade Flowise to version 3.1.3, which fixes the validator bypass.
- If no patch: Restrict network access to Flowise instances (authentication, IP allow-listing, VPN), avoid exposing chatflows publicly, and disable or restrict CSV Agent / Airtable Agent chatflows that permit Python execution until the upgrade is applied.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Flowise - Build AI Agents, Visually,Flowise - Low-code LLM apps builder - Meta tag content:
FlowiseAI,Open source generative AI development platform for building AI agents - Raw response body:
data-rewardful="9a3a26",og:site_name,flowiseai.com

