Eval Injection in Flowise - CVE-2026-69264

 

Eval Injection in Flowise - CVE-2026-69264

Published: July 30, 2026


Vulnerability identifier: #VU140056
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69264
CWE-ID: CWE-95
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the CSVAgent component when processing a crafted csvFile data URI. A remote user can plant a crafted chatflow and trigger prediction execution to execute arbitrary code.

Exploitation requires the ability to create or update chatflows or agentflows, and the resulting malicious flow can then be triggered through the public prediction endpoint when the chatflow has no API key set.


Affected software

Flowise

How to mitigate CVE-2026-69264

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins