PT-2026-34729 · Flowise · Flowise

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41137

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description The CSVAgent allows the provision of custom Pandas CSV read code. Due to a lack of sanitization, an attacker can provide a command injection payload that is interpolated and executed by the server.
Recommendations Update to version 3.1.0.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41137
GHSA-9WC7-MJ3F-74XV

Affected Products

Flowise