Eval Injection in Flowise - CVE-2026-69264
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the CSVAgent component when processing a crafted csvFile data URI. A remote user can plant a crafted chatflow and trigger prediction execution to execute arbitrary code.
Exploitation requires the ability to create or update chatflows or agentflows, and the resulting malicious flow can then be triggered through the public prediction endpoint when the chatflow has no API key set.