{"id":"CVE-2026-69256","aliases":["GHSA-x6vm-w76m-8j7g"],"url":"https://o3.security/vulnerability/CVE-2026-69256","summary":"Flowise: Remote Code Execution Vulnerability in CSVAgent","details":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/<UUID> to execute commands. This issue is fixed in version 3.1.3.","published":"2026-08-04T15:45:55.039Z","modified":"2026-09-16T03:47:17.880849282Z","cvss":null,"epss":{"score":0.0039,"percentile":0.32226,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"flowise-components","fixedVersion":"3.1.3"},{"ecosystem":"npm","name":"flowise","fixedVersion":"3.1.3"}],"fix":{"url":"https://github.com/FlowiseAI/Flowise/commit/c79fe56a6c249850e96bce9b4859f7a0083e4507","label":"FlowiseAI/Flowise@c79fe56"},"references":[{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69256.json"},{"type":"ADVISORY","url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69256"},{"type":"FIX","url":"https://github.com/FlowiseAI/Flowise/commit/c79fe56a6c249850e96bce9b4859f7a0083e4507"},{"type":"FIX","url":"https://github.com/FlowiseAI/Flowise/pull/6257"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:47:17.880849282Z"}}