Vulnerabilities/

Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

Severity:
High

Description

Flowise’s CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis (which on Node.

Recommendation

Update the flowise-components package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flowise-components
Anything's wrong? Let us know Last updated on August 04, 2026