CVE-2026-41137: Flowise: Code Injection in CSVAgent leads to Authenticated RCE
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the server. This vulnerability is fixed in 3.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41137?
CVE-2026-41137 is considered a critical vulnerability due to its potential for authenticated remote code execution.
How do I fix CVE-2026-41137?
To fix CVE-2026-41137, update Flowise to version 3.1.0 or later where the vulnerability has been addressed.
What does CVE-2026-41137 affect?
CVE-2026-41137 affects Flowise versions prior to 3.1.0, specifically the CSVAgent feature.
What can an attacker do with CVE-2026-41137?
An attacker can exploit CVE-2026-41137 to conduct code injection leading to authenticated remote code execution.
Is my installation of Flowise vulnerable to CVE-2026-41137?
If you are using a version of Flowise prior to 3.1.0, your installation is vulnerable to CVE-2026-41137.