Remote Code Execution Vulnerability in Flowise by FlowiseAI
CVE-2026-69264

9.4CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-69264?

A security flaw in Flowise CSVAgent prior to version 3.1.3 allows attackers to inject malicious data into a Pyodide template. This exploitation can lead to unauthorized access where an attacker, armed with specific permissions, can craft a CSV file that triggers remote code execution. The vulnerability arises due to the lack of validation pathways around the bootstrapped template, enabling arbitrary file I/O and execution of OS commands. This vulnerability poses significant risks to deployments, as it can be exploited via any unauthenticated request that interacts with exposed chatflows.

Affected Version(s)

Flowise < 3.1.3

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.