CVE-2026-69255 carries a CVSS 3.1 base score of 8.8 against Flowise, an open-source drag-and-drop interface for building customized large language model workflows. NVD classifies it as CWE-94 (Improper Control of Generation of Code) and states the flaw is fixed in version 3.1.3, meaning all earlier versions are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 15, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-69255 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description locates the flaw in Flowise’s CSVAgent component, which extracts attacker-controlled data from an uploaded CSV file and interpolates it directly into a Python code string before that code is executed in Flowise’s embedded Python runtime (Pyodide). NVD states the component’s existing safety check — a denylist meant to catch dangerous code — only validated code generated later in the pipeline by the LLM itself, and never validated this earlier, CSV-derived code block at all. An attacker with authenticated access to submit CSV data, per the CVSS vector’s PR:L (low privileges required), could manipulate that input to break out of the interpolated string context and reach the underlying JavaScript execution bridge Pyodide runs on top of, from which NVD states arbitrary operating system commands can be executed as root inside the Flowise container.
We are reporting the vulnerable component, the missing validation, and the resulting impact — not the specific input construction needed to escape the string context, which is exactly the technical reproduction detail this publication does not carry regardless of what a source document contains.
Evidence and confidence
- Medium confidence — the CVSS 8.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the CWE-94 classification, the fixed version (3.1.3), and the vulnerable component and validation gap all trace to NVD alone, corroborated by FlowiseAI’s own linked GitHub security advisory and commit fixing the issue. The exploitation report traces to VulnCheck KEV alone. - Above-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00602, a 47.2nd percentile score as of our ingestion.
No field is in conflict between our two sources.
Why this matters
This is a case where a security control existed but had a gap in its own coverage: the denylist meant to prevent dangerous code execution only checked code the LLM itself generated, leaving an earlier, attacker-reachable code-construction step completely unvalidated. That pattern — a defense that covers the obvious late-stage risk but misses an earlier step in the same pipeline — is a recurring failure mode in AI-tooling platforms that chain multiple code-generation and execution stages together, and worth watching for in similar tools even beyond this specific CVE.
Because the flaw requires only low privileges (an authenticated but not necessarily administrative account) and results in root-level command execution inside the container, any Flowise deployment that allows multiple users to submit CSV data — a common workflow-building pattern — should be treated as exposed until upgraded, regardless of how much the operator trusts individual account holders.
Frequently Asked Questions
What is CVE-2026-69255? A CVSS 8.8 code injection vulnerability (CWE-94) in Flowise’s CSVAgent component, fixed in version 3.1.3, allowing an authenticated low-privilege attacker to escape interpolated Python code and execute arbitrary OS commands as root in the Flowise container.
Is CVE-2026-69255 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 15, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.
Do I need administrator access to exploit this? No. The CVSS vector indicates only low privileges are required — an ordinary authenticated account with access to submit CSV data to the CSVAgent component is sufficient, per NVD’s description.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Version 3.1.3, per NVD and FlowiseAI’s own release tag.
Severity, vector, weakness classification, and the vulnerable component and validation gap sourced from the National Vulnerability Database record for CVE-2026-69255, corroborated by FlowiseAI’s own GitHub security advisory and fix commit. Exploitation status and the September 15, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.