ZDI-CAN-30459: ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability
Published Sep 9, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.
Affected Software
1 affected component
Flowise
Event History
Sep 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Does exploitation require authentication?
No. Remote attackers do not need to authenticate to exploit this vulnerability.
2
What impact can successful exploitation have?
Successful exploitation allows an attacker to execute arbitrary code on an affected Flowise installation.