Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-69255

9.2CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-69255?

The Flowise platform, designed for creating customized large language model flows, is affected by a vulnerability in the CSVAgent component. Prior to version 3.1.3, the CSVAgent improperly handled attacker-controlled CSV data, enabling crafted input to be integrated directly into executable Python code. This vulnerability allows an authenticated attacker to manipulate the CSV input, inject malicious code, and leverage Pyodide's JavaScript bridge to execute arbitrary commands on the underlying operating system as root. The issue has since been addressed in the latest release.

Affected Version(s)

Flowise < 3.1.3

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.