Vulnerabilities/

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

Severity:
High

Description

This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-components
Anything's wrong? Let us know Last updated on August 04, 2026