Description
The CSVAgent node was observed to allow users to write Python code which gets executed via pyodide. The original intent was to allow users to utilise the pandas library for CSV processing.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.2
- Patched version(s): 3.1.3
References
Related Issues
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
- Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability - CVE-2026-41265
- Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas - CVE-2026-41138
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - flowise-components - CVE-2026-70477
You might also like:
- Tags:
- npm
- flowise-components
Anything's wrong? Let us know Last updated on August 04, 2026


