ZDI-CAN-30461: ZDI-26-545: Flowise CSV_Agent customReadCSV Code Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-69256.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30461?
ZDI-CAN-30461 has a CVSS rating of 8.8, indicating a high severity level.
How do I fix ZDI-CAN-30461?
To fix ZDI-CAN-30461, ensure you update to the latest patched version of Flowise that addresses this remote code execution vulnerability.
What type of vulnerability is ZDI-CAN-30461?
ZDI-CAN-30461 is a code injection vulnerability that allows for remote code execution on affected Flowise installations.
Is authentication required to exploit ZDI-CAN-30461?
Yes, authentication is required to exploit the ZDI-CAN-30461 vulnerability.
What is the potential impact of ZDI-CAN-30461 on my system?
The potential impact of ZDI-CAN-30461 includes unauthorized execution of arbitrary code, which could compromise system security.