Description
The CSVAgent node was observed to allow users to write Python code which gets executed via pyodide. The original intent was to allow users to utilise the pandas library for CSV processing.
Recommendation
Update the flowise-components package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.1.2
- Patched version(s): 3.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Flowise: Remote Code Execution Vulnerability in CSVAgent and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
- Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability - CVE-2026-41265
- Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas - CVE-2026-41138
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - flowise-components - CVE-2026-70477


