ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

highAdvisoryimportance 40CVE-2026-70477
AI summary · glm-5.3-flash

ZDI disclosed a CVSS 9.8 unauthenticated prompt injection vulnerability in Flowise's CSV agent that allows remote arbitrary code execution.

ZDI published advisory ZDI-26-634 for a prompt injection vulnerability in Flowise's CSV agent component. Remote, unauthenticated attackers can inject prompts to execute arbitrary code on affected installations. ZDI assigned CVSS 9.8 and the issue is tracked as CVE-2026-70477.

  • Prompt injection leads to remote code execution in Flowise
  • No authentication required for exploitation
  • ZDI rated the issue CVSS 9.8
  • Tracked as CVE-2026-70477

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-70477
Flowise is a drag & drop user interface to build a customized large language model flow.

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.

NVD description · AI analysis pending
9.5<1%
  • flowiseai flowise
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.

This source does not provide full text. Read it at zerodayinitiative.com.