Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9wc7-mj3f-74xv | Flowise: Code Injection in CSVAgent leads to Authenticated RCE |
Mon, 27 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai flowise-components
|
|
| Vendors & Products |
Flowiseai flowise-components
|
Fri, 24 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| Metrics |
cvssV3_1
|
Thu, 23 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the server. This vulnerability is fixed in 3.1.0. | |
| Title | Flowise: Code Injection in CSVAgent leads to Authenticated RCE | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-23T20:20:30.780Z
Reserved: 2026-04-17T12:59:15.738Z
Link: CVE-2026-41137
Updated: 2026-04-23T20:20:26.372Z
Status : Analyzed
Published: 2026-04-23T20:16:14.257
Modified: 2026-04-24T15:15:47.703
Link: CVE-2026-41137
No data.
OpenCVE Enrichment
Updated: 2026-04-28T07:30:26Z
Github GHSA