A vulnerability marked as critical has been reported in FlowiseAI Flowise up to 3.1.2. The impacted element is the function
pd.read_json of the component Agent Node. This manipulation causes code injection.
This vulnerability is tracked as CVE-2026-73487. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.