Flowise disclosed and fixed CVE-2026-69255, a high-severity remote code execution flaw in the CSVAgent component affecting versions earlier than 3.1.3. The bug stemmed from attacker-controlled CSV content being inserted directly into executable Python before being passed to Pyodide, allowing code injection. Because Flowise validated only later LLM-generated code and not the initial Python block, an attacker could escape the intended string context, pivot through Pyodide's JavaScript bridge, reach Node.js child_process, and execute arbitrary operating system commands as root inside the Flowise container.
A related Flowise GitHub commit shows the vendor removed both CSVAgent and AirtableAgent and deleted Python code validation functionality as part of the security response. The change also removed the pyodide dependency and deleted more than 1,600 lines of code, indicating a broad rollback of the affected feature set rather than a narrow patch. The vulnerability is tracked as CWE-94 and is addressed in Flowise 3.1.3.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry, CVE-2026-70477, was received for a Flowise CSV Agent prompt-injection flaw that can lead to arbitrary code execution via malicious Python generated and executed in an unsandboxed Pyodide environment. The advisory says the issue is fixed in Flowise 3.1.3 and references Flowise PR #6499, the fix commit, and GitHub Security Advisory GHSA-5xvg-pmgg-3mxr.
The CVE entry states that CVE-2026-69255, a Flowise CSVAgent code-injection flaw leading to remote code execution, was newly received by security-advisories@github.com. The issue affects Flowise versions earlier than 3.1.3 and is tracked in GitHub Security Advisory GHSA-vmv7-4m6c-3cg5.
A verified Flowise Git commit removed the CSVAgent and AirtableAgent components, deleted Python code validation files, and removed the pyodide dependency, with the commit message stating the components were removed due to security vulnerabilities. This commit is referenced as the fix associated with Flowise issue 606 and pull request #6499.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.