Skip to content

MCPA-2026-0026

criticalrce-vectors

Flowise CSV Agent remote code execution via Pyodide code injection (CVE-2026-69255)

Flowise 3.1.2 and earlier allow code injection through the CSV Agent: attacker-controlled input reaches the Pyodide Python execution environment and escapes it, achieving remote code execution on the host (root shell verified by the reporter). Affects the flowise and flowise-components npm packages. Fixed in 3.1.3.

Affected packages

EcosystemPackageAffected versions
npmflowise
>= 0, < 3.1.3
npmflowise-components
>= 0, < 3.1.3

Identifiers

CVE-2026-69255GHSA-vmv7-4m6c-3cg5CWE-94

References

Timeline

  • Published: 2026-08-04

← All advisories