A vulnerability marked as critical has been reported in FlowiseAI Flowise up to 3.1.2. The impacted element is the function pd.read_json of the component Agent Node. This manipulation causes code injection.

This vulnerability is tracked as CVE-2026-73487. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.