
Flowise (npm) versions <= 3.1.2 ship a critical RCE in the CSV Agent node. A prompt injection in the agent input makes the LLM emit a malicious Python script that escapes the sandbox and runs arbitrary code on the host. CVE-2026-70477, GHSA-5xvg-pmgg-3mxr. Fixed in 3.1.3. https://hol.org/guard/security/cves
Post summary
Flowise npm versions <= 3.1.2 contain a critical RCE via prompt injection that escapes the sandbox, but the issue has been fixed in version 3.1.3.
