PT-2026-34236 · Flowise · Flowise

Published

2026-04-21

·

Updated

2026-04-27

·

CVE-2026-41264

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description A flaw exists in the run method of the CSV Agents class due to improper sandboxing when evaluating Python scripts generated by a Large Language Model (LLM). An unauthenticated attacker can use prompt injection techniques to convince the LLM to generate a malicious Python script. Because the input validation in the validatePythonCodeForDataFrame() function can be bypassed, this allows the execution of arbitrary commands on the server in the context of the user running the service.
Recommendations Update to version 3.1.0. As a temporary workaround, restrict access to the CSV Agent node to minimize the risk of exploitation.

Exploit

Fix

RCE

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41264
GHSA-3HJV-C53M-58JJ

Affected Products

Flowise