CVE-2026-70477
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
Erwähnungen (letzte 60 Tage)
EPSS-Score
0.8%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-70477 betrifft FlowiseAI Flowise vor Version 3.1.3 und stellt eine kritische Prompt Injection Schwachstelle dar. Ein Angreifer kann über einen CSV Agent Node eine bösartige Python-Skriptausführung im Kontext des Dienstkontos erzwingen. Dies umgeht die Blocklist-Validierung und führt zu beliebiger Codeausführung in einer unsandboxed Pyodide-Umgebung. Die Schwachstelle liegt in der run-Methode der CSV_Agents-Klasse, wo unvertrauenswürdige Daten zur Erstellung eines LLM-Prompts verwendet werden. Mit einem CVSS-Score von 9.8 (CRITICAL) ist diese Schwachstelle als extrem schwerwiegend einzustufen. Obwohl die EPSS-Wahrscheinlichkeit für einen Exploit derzeit bei nur 1% liegt und die Schwachstelle nicht in CISA's KEV-Katalog aufgeführt ist, deutet die hohe Kritikalität auf ein erhebliches Risiko hin. Security-Teams sollten umgehend alle FlowiseAI Flowise-Instanzen auf Version 3.1.3 oder höher aktualisieren, um diese kritische Schwachstelle zu beheben. Eine schnelle Patch-Implementierung ist aufgrund der Möglichkeit der beliebigen Codeausführung dringend erforderlich, um die Integrität und Sicherheit der Systeme zu gewährleisten.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.
Betroffene Produkte
- cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
GitHub Advisories
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Referenzen
- https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304...
- https://github.com/FlowiseAI/Flowise/pull/6499
- https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr