Researchers at elttam disclosed six remote code execution vulnerabilities in the Flowise AI agent and workflow platform, affecting versions 3.1.1 and 3.1.2. The flaws could allow attackers to execute code on exposed Flowise servers, raising concerns for organizations using the platform to orchestrate AI workflows and integrations.
Reporting on the issue also referenced Flowise-related local and container paths and endpoints tied to authentication, document processing, and custom function handling, including sensitive files such as /proc/self/environ and /root/.flowise/database.sqlite. Those details suggest attackers could pursue local file access and post-exploitation activity after initial compromise, adding to concerns around Flowise's recurring history of critical security advisories.

Track how attackers are adapting to this technology.
12 events from the most recent confirmed update back to the earliest known activity.
Flowise remediated CVE-2026-69256, a critical authenticated RCE in CSVAgent where attacker-controlled customReadCSVFunc input could invoke pandas.read_pickle() to deserialize a malicious pickle payload and execute commands. The issue affected versions prior to 3.1.3 and is linked to commit c79fe56a6c249850e96bce9b4859f7a0083e4507, pull request #6257, and GitHub advisory GHSA-x6vm-w76m-8j7g.
Flowise remediated CVE-2026-69259, an authenticated RCE in the SQLite Record Manager node where user-controlled additionalConfig could override the SQLite database path and, in the root-running Docker image, be leveraged to place crafted files such as /etc/chromium/*.conf for code execution when Chromium launched. The issue affected versions earlier than 3.1.3 and is linked to commit d07186844263bad057008863037466aff7c3390f, pull request #6464, and GitHub advisory GHSA-x3hf-7cj6-3r4m.
Flowise remediated CVE-2026-69263, an unauthenticated RCE in Custom MCP server launches that bypassed an earlier CVE-2025-8943 mitigation by using the npm_config_yes environment variable to make npx auto-install and execute a named package. The flaw affected versions prior to 3.1.3 and was fixed in Flowise version 3.1.3.
Flowise remediated CVE-2026-69264, a critical RCE in CSVAgent where an attacker-controlled csvFile data URI segment was interpolated into a Pyodide-executed Python template without validation, enabling breakout to JavaScript and host-level command execution. The advisory ties the fix to version 3.1.3, commit f4e2794f6a576b94578f2fdafbf49c2fb304626c, pull request #6499, and GitHub advisory GHSA-4j8x-x6v7-w9rq.
Flowise remediated CVE-2026-70470, a critical remote code execution flaw in the Pyodide Python code validator that allowed a Unicode homoglyph blacklist bypass leading to arbitrary Python and host OS command execution. The advisory ties the fix to Flowise version 3.1.3, commit f4e2794f6a576b94578f2fdafbf49c2fb304626c, pull request #6499, and GitHub advisory GHSA-52fh-8v99-63c2.
Flowise remediated CVE-2026-69251, a critical authenticated RCE caused by unsafe handling of TypeORM DataSource options in record manager and agent memory nodes that allowed arbitrary JavaScript payload execution via entities, subscribers, or migrations. The advisory says the issue affected Flowise and flowise-components before version 3.1.3 and is tracked in GitHub advisory GHSA-g32j-mmxr-gfq5.
Flowise remediated CVE-2026-69253, a critical authenticated RCE caused by code injection through a user-controlled baseURL in AgentAsTool, ChatflowTool, and ExecuteFlow that enabled vm2 sandbox escape. The advisory ties the fix to version 3.1.3, commit 3f257bdc8196082a178da7134a075824401b13b9, pull request #6417, and GitHub advisory GHSA-wg86-r78f-74mp.
Flowise remediated CVE-2026-69254, an authenticated RCE caused by a NodeVM sandbox escape in executeJavaScriptCode(), by releasing version 3.1.3. The advisory links the fix to commit 3086cb7e323bb96c5a581d3232ef975b0d92183d, pull request #6306, and GitHub advisory GHSA-3769-jgqc-cxm7.
Researchers bypassed Flowise's initial patch for an unvalidated SQLite path in the SQL Database Chain node, retaining an arbitrary file-write path that could be chained with Chromium launcher behavior for RCE. Flowise had deferred a fix for this bypass at the time of the report's publication.
Security updates were released for Flowise after public disclosure of multiple vulnerabilities affecting versions up to and including 3.1.2. The newly referenced issues include CVE-2026-70476, CVE-2026-70474, CVE-2026-70473, CVE-2026-69257, and CVE-2026-69255, spanning billing and resource-accounting manipulation, OAuth/authentication bypass, SSRF protection bypass, and CSVAgent code execution.
Flowise merged pull request #6499, which removed AirtableAgent and CSVAgent due to security vulnerabilities. The change was merged into the main branch as commit f4e2794 after review and passing checks.
Security researchers at elttam reported six new remote code execution vulnerabilities affecting the Flowise AI agent and workflow platform. The issues were identified in Flowise versions 3.1.1 and 3.1.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
15 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceelttam.com
Open sourcegithub.com
Open sourcereddit.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.