
🚨 Active exploitation detected for multiple high-severity vulnerabilities, including CVE-2026-69255 and CVE-2023-54398. Patch now to prevent attacks #ThreatIntel #CyberSecurity #InfoSec https://pranithjain.qzz.io/threatintel/telegram?tab=leaks
Exploit discussion active in current signal (1 latest mentions)
Recommended action window: High priority (within 72h)
NVD description
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.
Priority
MEDIUM
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-08-04 | 1 | Exploit1 |
| 2026-08-06 | 1 | PoC1 |

🚨 Active exploitation detected for multiple high-severity vulnerabilities, including CVE-2026-69255 and CVE-2023-54398. Patch now to prevent attacks #ThreatIntel #CyberSecurity #InfoSec https://pranithjain.qzz.io/threatintel/telegram?tab=leaks

csirt_it: ‼️ #Flowise: #PoC per CVE-2026-70476, CVE-2026-70474, CVE-2026-70473, CVE-2026-70470, CVE-2026-69264, CVE-2026-69263, CVE-2026-69257, CVE-2026-69256 e CVE-2026-69255 Rischio: 🔴 Tra le tipologie 🔸 Information Disclosure 🔗 … https://t.co/N9ohNZ3AC1
Post summary
PoC for a series of CVE‑2026 vulnerabilities are announced, indicating potential information disclosure risk, but no active exploitation or patch information is provided.

🚨Critical - Flowise CSVAgent Remote Code Execution to Root (CVE-2026-69255) Flowise's CSVAgent node interpolates uploaded CSV / data-URI content directly into an executable Python string with no sanitization, and its denylist only covers later LLM-generated code - not this block. A crafted input breaks out of the string and runs attacker Python. From the pyodide sandbox, that pivots to the host Node.js process to run arbitrary OS commands. It's been verified to a root shell, with credential theft, arbitrary file read, and DoS, and a public exploit module exists. CVSS 9.2 (advisory notes 9.9). 👉Upgrade flowise and flowise-components to 3.1.3 (also fixes CVE-2026-69256), and keep Flowise off untrusted networks.
Post summary
A critical RCE in Flowise’s CSVAgent allows root via a public exploit module; updating to version 3.1.3 mitigates the issue.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | flowiseai | flowise | - | - | - |