Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-69255
9.2CRITICAL
What is CVE-2026-69255?
The Flowise platform, designed for creating customized large language model flows, is affected by a vulnerability in the CSVAgent component. Prior to version 3.1.3, the CSVAgent improperly handled attacker-controlled CSV data, enabling crafted input to be integrated directly into executable Python code. This vulnerability allows an authenticated attacker to manipulate the CSV input, inject malicious code, and leverage Pyodide's JavaScript bridge to execute arbitrary commands on the underlying operating system as root. The issue has since been addressed in the latest release.
Affected Version(s)
Flowise < 3.1.3
