Skip to content

MCPA-2026-0050

criticalrce-vectors

Flowise Pyodide validator Unicode homoglyph bypass leads to RCE (CVE-2026-70470)

Flowise 3.1.2 and earlier validate Pyodide code with a blocklist that can be bypassed using Unicode homoglyphs, letting authenticated users execute arbitrary code outside the sandbox. Fixed in 3.1.3.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.3
npmflowise-components
>= 0, < 3.1.3

Identifiers

CVE-2026-70470GHSA-52fh-8v99-63c2CWE-184

References

Timeline

  • Published: 2026-08-04

← All advisories