CVE-2026-41265Disclosure(flowiseai / flowise)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using the Airtable Agent node may convince an LLM to respond with a malicious python script that executes attacker controlled commands on the flowise server. This vulnerability is fixed in 3.1.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-05: 1Mentions · 2026-06-13: 1Technical Details · 2026-05-05: 1Technical Details · 2026-06-13: 105-0506-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-307|CVE-2026-41265] FlowiseAI Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Dre Cura (@dre_cura) and Nicholas Zubrisky (@NZubrisky) of TrendAI Research) https://www.zerodayinitiative.com/advisories/ZDI-26-307/

    Post summary

    An advisory announces a high‑severity remote code execution flaw (CVE‑2026‑41265) in FlowiseAI Airtable_Agent, but provides no PoC code, exploit details, or evidence of active exploitation.

    020411.1K
    5.6K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-41265: Flowise Airtable Agent Prompt Injection Leading to Remote Code Execution - What It Means for Your Business and How to Respond https://hubs.li/Q04lk8jd0

    Post summary

    The text announces CVE‑2026‑41265, identifies it as a prompt injection flaw that can trigger remote code execution in Flowise Airtable Agent, but provides no evidence of active exploitation, PoC, or specific patch information.

    0000034
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more