MCPA-2026-0049
criticalrce-vectors
Flowise CSV Agent prompt-injection remote code execution (CVE-2026-70477)
Flowise 3.1.2 and earlier allow prompt-injection content processed by the CSV Agent to reach the Python execution path and run arbitrary code on the host — a toxic flow from untrusted data to code execution. Fixed in 3.1.3.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, < 3.1.3 |
| npm | flowise-components | >= 0, < 3.1.3 |
Identifiers
CVE-2026-70477GHSA-5xvg-pmgg-3mxrCWE-94
References
- advisory https://github.com/advisories/GHSA-5xvg-pmgg-3mxr
- advisory https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr
- web https://nvd.nist.gov/vuln/detail/CVE-2026-70477
Timeline
- Published: 2026-08-04