{"cve":{"cve_id":"CVE-2026-70477","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00833,"epss_percentile":0.55692,"epss_as_of":"2026-09-15","description":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.","published_at":"2026-08-04T19:29:14.796000Z","last_modified_at":"2026-09-11T21:09:26.917000Z","cvss_v3_score":9.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":9.5,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","cvss_v4_severity":"CRITICAL","ssvc_decision":null,"ssvc_exploitation":"poc","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":["CWE-94"],"nvd_references":["https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr","https://github.com/FlowiseAI/Flowise/pull/6499","https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-08-04T21:40:38.289974Z","updated_at":"2026-09-12T23:39:39.811254Z"},"effective_severity":"CRITICAL","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"H","value_label":"High"},{"metric":"AT","name":"Attack Requirements","value":"P","value_label":"Present"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"H","value_label":"High"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"H","value_label":"High"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"H","value_label":"High"},{"metric":"SA","name":"Availability (Subsequent System)","value":"H","value_label":"High"}]},"affected":[{"vendor_slug":"flowiseai","vendor_name":"FlowiseAI","product_slug":"flowise","product_name":"Flowise","version_start":"< 3.1.2","version_start_inclusive":true,"version_end":"< 3.1.2","version_end_inclusive":true,"cpe23_uri":"cve5:flowiseai:flowise:< 3.1.2:< 3.1.2"},{"vendor_slug":"flowiseai","vendor_name":"FlowiseAI","product_slug":"flowise","product_name":"Flowise","version_start":null,"version_start_inclusive":null,"version_end":"3.1.3","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*"}],"exploit_refs":[],"news":[],"references":[{"url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://github.com/FlowiseAI/Flowise/pull/6499","source_type":"PATCH","tags":["patch"]},{"url":"https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c","source_type":"PATCH","tags":["patch"]},{"url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3","source_type":"PATCH","tags":["patch"]}],"timeline":[{"type":"published","at":"2026-08-04T19:29:14.796000Z","label":"CVE published","source":null},{"type":"ssvc_changed","at":"2026-08-05T15:41:38.287103Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-08-05T15:41:38.287103Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-08-05T15:41:38.287103Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-09-12T23:39:39.811254Z","label":"CVSS score revised","source":"nvd"},{"type":"cvss_changed","at":"2026-09-12T23:39:39.811254Z","label":"CVSS score revised","source":"nvd"},{"type":"cvss_changed","at":"2026-09-12T23:39:39.811254Z","label":"CVSS score revised","source":"nvd"}]}