<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:57:28.243895+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348496</id>
    <title>EUVD-2026-348496</title>
    <updated>2026-10-02T14:57:28.246564+00:00</updated>
    <content>EUVD-2026-348496</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69256</id>
    <title>fkie_cve-2026-69256</title>
    <updated>2026-10-02T14:57:28.246593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/&lt;UUID&gt; to execute commands. This issue is fixed in version 3.1.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x6vm-w76m-8j7g</id>
    <title>GHSA-x6vm-w76m-8j7g — Flowise: Remote Code Execution Vulnerability in CSVAgent</title>
    <updated>2026-10-02T14:57:28.246629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: flowise-components, npm: flowise</p>
<p>### Summary</p>
<p>The CSVAgent node was observed to allow users to write Python code which gets executed via `pyodide`. The original intent was to allow users to utilise the `pandas` library for CSV processing. Although there is a denylist that checks for dangerous Python constructs from being passed in, `pandas` has a `read_pickle()` [function](https://pandas.pydata.org/docs/reference/api/pandas.read_pickle.html) that deserialises a pickled payload and this can be leveraged to achieve code execution.</p>
<p>### Details</p>
<p>The affected file is the `CSVAgent` node, found in: `flowise-components/nodes/agents/CSVAgent/CSVAgent.ts`.</p>
<p>```js
try {
    const code = `import pandas as pd
import base64
from io import StringIO
import json</p>
<p>base64_string = "${base64String}"</p>
<p>decoded_data = base64.b64decode(base64_string)</p>
<p>csv_data = StringIO(decoded_data.decode('utf-8'))</p>
<p>df = pd.${customReadCSVFunc} &lt;1&gt;
my_dict = df.dtypes.astype(str).to_dict()
print(my_dict)
json.dumps(my_dict)`
    dataframeColDict = await pyodide.runPythonAsync(code)
} catch (error) {
    throw new Error(error)
}
```</p>
<p>At &lt;1&gt;, the `customReadCSVFunc` is supplied by the user. This input goes through input validation that denies dangerous Python constructs from being passed in:</p>
<p>```py
const FORBIDDEN_PATTERNS: Array&lt;{ pattern: RegExp; reason: string }&gt; = [
    // Imports (the executor pre-imports pandas and numpy; LLM code must not add any imports)
    { pattern: /\bfrom\s+\S+\s+import\b/g, reason: 'import statement (from...import)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x6vm-w76m-8j7g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</id>
    <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:57:28.246693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589"/>
  </entry>
</feed>
