Vulnerability GHSA-5xvg-pmgg-3mxr
Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 months ago
August 04, 2026 at 07:29 PM UTC
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
1.0.0 - 3.1.2
1.0.0 - 3.1.2
Summary
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Details
-- ABSTRACT -------------------------------------
Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: Flowise - Flowise
-- VULNERABILITY DETAILS ------------------------
- Version tested: 3.1.1
- Installer file: https://github.com/FlowiseAI/Flowise (npm install [email protected])
- Platform tested: Ubuntu 25.10
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
3 hours ago
Flowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
1.0.0 - 3.1.2 GHSA-w7x8-q2gp-5cgg
1.0.0 - 3.1.2 GHSA-w7x8-q2gp-5cgg
Critical
3 hours ago
Flowise Prompt Injection to RCE and SSRF via CSV/Airtable Agent Python Validator Bypass
1.0.0 - 3.1.2 GHSA-w7x8-q2gp-5cgg
1.0.0 - 3.1.2 GHSA-w7x8-q2gp-5cgg
Critical
3 hours ago
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
1.0.0 - 3.1.2 GHSA-9gvv-qjj3-2p6g
1.0.0 - 3.1.2 GHSA-9gvv-qjj3-2p6g
Critical
3 hours ago
Flowise NodeVM sandbox escape via puppeteer allowlist - authenticated RCE and arbitrary file read via Chromium
1.0.0 - 3.1.2 GHSA-9gvv-qjj3-2p6g
1.0.0 - 3.1.2 GHSA-9gvv-qjj3-2p6g
Critical
2 months ago
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
1.0.0 - 3.1.2 GHSA-qgvm-j2hm-6m38
1.0.0 - 3.1.2 GHSA-qgvm-j2hm-6m38
Impacted packages
Timeline
Published
2 months ago
August 04, 2026 at 07:29 PM UTC
Fixed (3.1.3)
3 months ago
June 25, 2026 at 10:35 AM UTC
Fixed (3.1.3)
3 months ago
June 25, 2026 at 10:41 AM UTC
Last Modified
2 months ago
August 04, 2026 at 07:56 PM UTC