Flowise pre-3.1.0: RCE via prompt injection in CSV/Airtable agents and MCP adapter
Three vulnerabilities in FlowiseAI's Flowise LLM flow builder prior to version 3.1.0 allow remote code execution on the server: unauthenticated attackers can use prompt injection against chatflows using the CSV Agent or Airtable Agent nodes to have the LLM emit unsandboxed Python that runs attacker commands, while an authenticated user can abuse unsafe serialization of stdio commands in the MCP adapter to execute arbitrary commands. All three are fixed in Flowise 3.1.0.
Disclosed 21 April 2026 · Record updated 13 September 2026
Impact
Attackers able to send prompts to affected chatflows could execute arbitrary code in the context of the user running the Flowise server; an authenticated user could also achieve command execution through the Custom MCP stdio configuration.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40933
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41264
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41265
