MCPA-2026-0050
criticalrce-vectors
Flowise Pyodide validator Unicode homoglyph bypass leads to RCE (CVE-2026-70470)
Flowise 3.1.2 and earlier validate Pyodide code with a blocklist that can be bypassed using Unicode homoglyphs, letting authenticated users execute arbitrary code outside the sandbox. Fixed in 3.1.3.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, < 3.1.3 |
| npm | flowise-components | >= 0, < 3.1.3 |
Identifiers
CVE-2026-70470GHSA-52fh-8v99-63c2CWE-184
References
- advisory https://github.com/advisories/GHSA-52fh-8v99-63c2
- advisory https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-52fh-8v99-63c2
- web https://nvd.nist.gov/vuln/detail/CVE-2026-70470
Timeline
- Published: 2026-08-04