ZDI-26-365: FlowiseAI Flowise CSV Agent customReadCSV Code Injection Remote Code Execution Vulnerability
Published Jun 24, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-41137.
Affected Software
1 affected component
FlowiseAI Flowise
Event History
Jun 24, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-365?
The severity of ZDI-26-365 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-26-365?
To fix ZDI-26-365, update FlowiseAI Flowise to the latest patched version that addresses the vulnerability.
3
What types of attacks can ZDI-26-365 facilitate?
ZDI-26-365 can facilitate remote code execution attacks by allowing attackers to execute arbitrary code.
4
Is authentication required to exploit ZDI-26-365?
Yes, authentication is required to exploit ZDI-26-365, but it can be bypassed.
5
What software is affected by ZDI-26-365?
The vulnerability ZDI-26-365 affects FlowiseAI Flowise installations.