<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:40:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-348517</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348517</link>
      <description>EUVD-2026-348517</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348517</guid>
    </item>
    <item>
      <title>fkie_cve-2026-70477</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-70477</link>
      <description>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Flowise is a drag &amp;amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-70477</guid>
    </item>
    <item>
      <title>GHSA-5xvg-pmgg-3mxr — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5xvg-pmgg-3mxr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;-- ABSTRACT -------------------------------------&lt;/p&gt;
&lt;p&gt;Trend Micro&amp;#39;s Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise - Flowise&lt;/p&gt;
&lt;p&gt;-- VULNERABILITY DETAILS ------------------------
* Version tested: 3.1.1
* Installer file: https://github.com/FlowiseAI/Flowise (npm install flowise@3.1.1)
* Platform tested: Ubuntu 25.10&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;A prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed pyodide environment. An attacker can leverage this to execute arbitrary code in the context of the user running the server.&lt;/p&gt;
&lt;p&gt;```
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the run method of the CSV_Agents class. The issue results from insufficient input sanitization when using untrusted data to construct an LLM prompt. An attacker can leverage this vulnerability to execute code in the context of the service account.
```&lt;/p&gt;
&lt;p&gt;### Analysis&lt;/p&gt;
&lt;p&gt;When a user makes a query against a chatflow using the CSV Agent node, the `run` method of the `CSV_Agents` class is called. This method reads the CSV file, loads a pyodide environment, and uses pandas to extract column names and data types into a dictionary. It then constructs a system prompt using that dictionary and the user&amp;#39;s input, and send…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: flowise, npm: flowise-components&lt;/p&gt;
&lt;p&gt;-- ABSTRACT -------------------------------------&lt;/p&gt;
&lt;p&gt;Trend Micro&amp;#39;s Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise - Flowise&lt;/p&gt;
&lt;p&gt;-- VULNERABILITY DETAILS ------------------------
* Version tested: 3.1.1
* Installer file: https://github.com/FlowiseAI/Flowise (npm install flowise@3.1.1)
* Platform tested: Ubuntu 25.10&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;A prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed pyodide environment. An attacker can leverage this to execute arbitrary code in the context of the user running the server.&lt;/p&gt;
&lt;p&gt;```
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the run method of the CSV_Agents class. The issue results from insufficient input sanitization when using untrusted data to construct an LLM prompt. An attacker can leverage this vulnerability to execute code in the context of the service account.
```&lt;/p&gt;
&lt;p&gt;### Analysis&lt;/p&gt;
&lt;p&gt;When a user makes a query against a chatflow using the CSV Agent node, the `run` method of the `CSV_Agents` class is called. This method reads the CSV file, loads a pyodide environment, and uses pandas to extract column names and data types into a dictionary. It then constructs a system prompt using that dictionary and the user&amp;#39;s input, and send…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5xvg-pmgg-3mxr</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2589 — Flowise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Flowise ausnutzen, um beliebigen Code auszuführen – sogar mit Root-Rechten –, erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Sitzungen zu kapern sowie Daten offenzulegen oder zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2589</guid>
    </item>
  </channel>
</rss>
