CVE-2026-69264: CWE-94: Improper Control of Generation of Code ('Code Injection') in FlowiseAI Flowise
CVE-2026-69264 is a critical remote code execution vulnerability in FlowiseAI Flowise versions prior to 3.1.3. It arises from improper control of code generation where attacker-controlled CSV data is interpolated into a Python source template executed by Pyodide. This allows an attacker with certain permissions to execute arbitrary OS commands via crafted CSV input, triggered by unauthenticated requests to the prediction API endpoint. The issue is fixed in version 3.1.3.
AI Analysis
Technical Summary
In FlowiseAI Flowise versions before 3.1.3, the CSVAgent component interpolates attacker-controlled segments of the csvFile data URI directly into a Python source-code template executed by Pyodide. Because Pyodide uses a default JavaScript bridge exposing powerful Node.js functions such as eval and dynamic import, an attacker can escape the Python string context to execute arbitrary JavaScript code. This enables dynamic import of Node.js built-in modules like fs and child_process, allowing arbitrary file I/O and OS command execution as the Flowise process. The vulnerability bypasses existing validators as they are not applied to the bootstrap template. A workspace user with chatflows:create or agentflows/chatflows update permissions can plant a malicious CSV Agent node. Once the chatflow is exposed via the POST /api/v1/prediction/:id endpoint, any unauthenticated request triggers remote code execution. The vulnerability is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with limited workspace permissions can achieve unauthenticated remote code execution on the host running Flowise by exploiting this vulnerability. This allows arbitrary file system access and OS command execution, leading to full compromise of the Flowise process environment. The vulnerability has a CVSS 4.0 score of 9.4 (critical), indicating high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
This vulnerability is fixed in Flowise version 3.1.3. Users should upgrade to version 3.1.3 or later to remediate this issue. No official temporary fixes or workarounds are provided. Until upgrading, restrict permissions to trusted users only and avoid exposing the vulnerable API endpoint to untrusted networks.
CVE-2026-69264: CWE-94: Improper Control of Generation of Code ('Code Injection') in FlowiseAI Flowise
Description
CVE-2026-69264 is a critical remote code execution vulnerability in FlowiseAI Flowise versions prior to 3.1.3. It arises from improper control of code generation where attacker-controlled CSV data is interpolated into a Python source template executed by Pyodide. This allows an attacker with certain permissions to execute arbitrary OS commands via crafted CSV input, triggered by unauthenticated requests to the prediction API endpoint. The issue is fixed in version 3.1.3.
CVSS v4.0
Score 9.4critical
Affected software
FlowiseAI
Flowise
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In FlowiseAI Flowise versions before 3.1.3, the CSVAgent component interpolates attacker-controlled segments of the csvFile data URI directly into a Python source-code template executed by Pyodide. Because Pyodide uses a default JavaScript bridge exposing powerful Node.js functions such as eval and dynamic import, an attacker can escape the Python string context to execute arbitrary JavaScript code. This enables dynamic import of Node.js built-in modules like fs and child_process, allowing arbitrary file I/O and OS command execution as the Flowise process. The vulnerability bypasses existing validators as they are not applied to the bootstrap template. A workspace user with chatflows:create or agentflows/chatflows update permissions can plant a malicious CSV Agent node. Once the chatflow is exposed via the POST /api/v1/prediction/:id endpoint, any unauthenticated request triggers remote code execution. The vulnerability is resolved in Flowise version 3.1.3.
Potential Impact
An attacker with limited workspace permissions can achieve unauthenticated remote code execution on the host running Flowise by exploiting this vulnerability. This allows arbitrary file system access and OS command execution, leading to full compromise of the Flowise process environment. The vulnerability has a CVSS 4.0 score of 9.4 (critical), indicating high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
This vulnerability is fixed in Flowise version 3.1.3. Users should upgrade to version 3.1.3 or later to remediate this issue. No official temporary fixes or workarounds are provided. Until upgrading, restrict permissions to trusted users only and avoid exposing the vulnerable API endpoint to untrusted networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-03T19:54:19.853Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a722805bf8831d53935abe2
Added to database: 08/04/2026, 17:57:25 UTC
Last enriched: 08/12/2026, 20:13:19 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.