CVE-2026-41264Active Exploitation(flowiseai / flowise)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can leverage this vulnerability to execute code in the context of the user running the server. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using the CSV Agent node may convince an LLM to respond with a malicious python script that executes attacker controlled commands on the Flowise server. This vulnerability is fixed in 3.1.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-06-24: 1Mentions · 2026-07-11: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-27: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-11: 104-2604-2706-2407-11
Signal classification2 categories
Active Exploitation
250.0%
Disclosure
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-261
Active Exploitation1
2026-04-271
Active Exploitation1
2026-06-241
Disclosure1
2026-07-111
Disclosure1
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-364|CVE-2026-41264] FlowiseAI Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Dre Cura (@dre_cura) and Nicholas Zubrisky (@NZubrisky) of TrendAI Research) https://www.zerodayinitiative.com/advisories/ZDI-26-364/

    Post summary

    The advisory announces CVE‑2026‑41264, a high‑severity remote code execution flaw in FlowiseAI Flowise CSV Agent caused by prompt injection, but no exploit or patch details are provided.

    02020656
    5.6K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-41264: FlowiseAI CSV Agent Critical RCE - Detection and Mitigation Gui… "A critical remote code execution vulnerability (CVE-2026-41264) has been discovered in…" 🔗 https://securityarsenal.com/blog/cve-2026-41264-flowiseai-csv-agent-critical-rce-detection-and-mitigation-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The post announces the discovery of a remote code execution vulnerability in FlowiseAI’s CSV Agent, providing a link to a detection and mitigation guide.

    00010103
    19 followersView on X
  • Build With AI@BuildWthAI
    Active Exploitation

    Flowise CSV Agent: prompt injection -> RCE. CVE-2026-41264, CVSS 10.0. Active exploitation in the wild, 12,000+ instances exposed. The "sandbox" was Pyodide. The agent generates Python from user prompts and runs it. Patched in 3.1.0. Upgrade today. https://t.co/7KIdM4khFT

    Post summary

    CVE-2026-41264 is a critical (CVSS 10.0) RCE triggered by prompt injection in Flowise CSV Agent, already being exploited in over 12,000 instances; a patch is available in version 3.1.0 and users are urged to update immediately.

    10000100
    7 followersView on X
  • Build With AI@BuildWthAI
    Active Exploitation

    Flowise CSV Agent: prompt injection → RCE. CVE-2026-41264, CVSS 10.0. Active exploitation in the wild, 12,000+ instances exposed. The "sandbox" was Pyodide. The agent generates Python from user prompts and runs it. Patched in 3.1.0. Upgrade today. https://t.co/zYBiRiwmBj

    Post summary

    CVE-2026-41264 is a prompt‑injection flaw that leads to remote code execution with a CVSS score of 10.0, has been actively exploited in over 12,000 instances in the wild, and is now fixed in version 3.1.0.

    0000092
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more