ZDI-CAN-29411: ZDI-26-364: FlowiseAI Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability
Published Jun 24, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-41264.
Affected Software
1 affected component
FlowiseAI Flowise CSV Agent
Event History
Jun 24, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-29411?
The severity of ZDI-CAN-29411 is rated at 9.8 on the CVSS scale.
2
What kind of vulnerability is ZDI-CAN-29411?
ZDI-CAN-29411 is a prompt injection remote code execution vulnerability affecting FlowiseAI Flowise CSV Agent.
3
Who can exploit ZDI-CAN-29411?
ZDI-CAN-29411 can be exploited by remote attackers without requiring authentication.
4
How can I fix ZDI-CAN-29411?
To fix ZDI-CAN-29411, update your FlowiseAI Flowise CSV Agent to the latest version.
5
What is the CVE associated with ZDI-CAN-29411?
The CVE associated with ZDI-CAN-29411 is CVE-2026-41264.