CVE-2026-69255Exploit(flowiseai / flowise)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch flowiseai flowise systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-08-04); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-04: 1Mentions · 2026-08-06: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-06: 1Exploit Tool / Code · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-06: 108-0408-0609-16
Signal classification2 categories
Exploit
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-041
Exploit1
2026-08-061
PoC1
Full discourse3 posts
  • PJ@Npj8448

    🚨 Active exploitation detected for multiple high-severity vulnerabilities, including CVE-2026-69255 and CVE-2023-54398. Patch now to prevent attacks #ThreatIntel #CyberSecurity #InfoSec https://pranithjain.qzz.io/threatintel/telegram?tab=leaks

    00000111
    72 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Flowise: #PoC per CVE-2026-70476, CVE-2026-70474, CVE-2026-70473, CVE-2026-70470, CVE-2026-69264, CVE-2026-69263, CVE-2026-69257, CVE-2026-69256 e CVE-2026-69255 Rischio: 🔴 Tra le tipologie 🔸 Information Disclosure 🔗 … https://t.co/N9ohNZ3AC1

    Post summary

    PoC for a series of CVE‑2026 vulnerabilities are announced, indicating potential information disclosure risk, but no active exploitation or patch information is provided.

    0000049
    628 followersView on X
  • Upwind Security MDR@UpwindMDR
    Exploit

    🚨Critical - Flowise CSVAgent Remote Code Execution to Root (CVE-2026-69255) Flowise's CSVAgent node interpolates uploaded CSV / data-URI content directly into an executable Python string with no sanitization, and its denylist only covers later LLM-generated code - not this block. A crafted input breaks out of the string and runs attacker Python. From the pyodide sandbox, that pivots to the host Node.js process to run arbitrary OS commands. It's been verified to a root shell, with credential theft, arbitrary file read, and DoS, and a public exploit module exists. CVSS 9.2 (advisory notes 9.9). 👉Upgrade flowise and flowise-components to 3.1.3 (also fixes CVE-2026-69256), and keep Flowise off untrusted networks.

    Post summary

    A critical RCE in Flowise’s CSVAgent allows root via a public exploit module; updating to version 3.1.3 mitigates the issue.

    00000135
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more