ZeroHour
Product

Flowise

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

Researchers counted 36,769 publicly reachable self-hosted AI endpoints, only about 2% behind HTTP authentication, exposing Ollama, vLLM, and Flowise to abuse.

A Mysterium VPN study found 36,769 self-hosted AI endpoints reachable through internet scanning, with only 2.02% returning an HTTP authentication challenge. Open WebUI accounted for 18,529 reachable instances, Ollama for 6,935 fingerprinted hosts, and 5,223 agent-builder and workflow platforms were exposed, often holding API keys, database credentials, and other secrets. The report highlights LLMjacking risk from exposed Ollama APIs, a critical Flowise bug (CVE-2026-40933), leaked n8n tokens, and prior SentinelOne/Censys research finding roughly 175,000 exposed Ollama hosts in 130 countries.

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

ZDI disclosed a CVSS 9.8 unauthenticated prompt injection vulnerability in Flowise's CSV agent that allows remote arbitrary code execution.

ZDI published advisory ZDI-26-634 for a prompt injection vulnerability in Flowise's CSV agent component. Remote, unauthenticated attackers can inject prompts to execute arbitrary code on affected installations. ZDI assigned CVSS 9.8 and the issue is tracked as CVE-2026-70477.

Related CVEs

  • Flowise is a drag & drop user interface to build a customized large language model flow.
    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the input sanitization from the “Custom MCP” configuration in http://localhost:3000/canvas - where any user can add a new MCP, when doing so - adding a new MCP using stdio, the user can add any command, even though your code have input sanitization checks such as…
    · flowiseai flowise PoC
  • Flowise is a drag & drop user interface to build a customized large language model flow.
    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in…
    · flowiseai flowise

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.