CVE-2026-69264 | FlowiseAI Flowise up to 3.1.2 CSVAgent validatePythonCodeForDataFrame csvFile os command injection

SecurityVulns

A vulnerability has been found in FlowiseAI Flowise up to 3.1.2 and classified as critical. Affected by this vulnerability is the function validatePythonCodeForDataFrame of the component CSVAgent. The manipulation of the argument csvFile leads to os command injection.

This vulnerability is listed as CVE-2026-69264. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More