Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-69264
9.4CRITICAL
What is CVE-2026-69264?
A security flaw in Flowise CSVAgent prior to version 3.1.3 allows attackers to inject malicious data into a Pyodide template. This exploitation can lead to unauthorized access where an attacker, armed with specific permissions, can craft a CSV file that triggers remote code execution. The vulnerability arises due to the lack of validation pathways around the bootstrapped template, enabling arbitrary file I/O and execution of OS commands. This vulnerability poses significant risks to deployments, as it can be exploited via any unauthenticated request that interacts with exposed chatflows.
Affected Version(s)
Flowise < 3.1.3
