目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-69264— Flowise CSVAgent CSV文件远程代码执行漏洞

CVSS 9.4 · Critical

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
FlowiseAIFlowise< 3.1.3affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-69264の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
ソース: CVE Program / CVE List V5
脆弱性説明
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval and dynamic import, the attacker can break out of the Python string literal, hand a JavaScript string to js.eval, dynamically import Node built-in modules such as fs and child_process, and execute arbitrary file I/O or OS commands as the Flowise process. The two validator paths around this code, validatePythonCodeForDataFrame and validateCustomReadCSVFunction, are never applied to the bootstrap template. A workspace user with chatflows:create or agentflows/chatflows update permission can plant a CSV Agent node with a crafted csvFile; once the chatflow is exposed via POST /api/v1/prediction/:id, any unauthenticated request triggers host remote code execution. This issue is fixed in version 3.1.3.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
对生成代码的控制不恰当(代码注入)
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
FlowiseAIFlowise < 3.1.3 -

II. CVE-2026-69264の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム
Qwen3.6-35B-A3B · 5446 文字数
Pro+限定の内容:
脆弱性再現の録画(実際のサンドボックス構築 + トリガー、限定)
脆弱性の原理を深く分析
トリガー条件と影響範囲
完全な実行可能POCコード
攻撃チェーンと緩和策の提案
POCパッケージのダウンロード
月間100件以上のAI生成枠

III. CVE-2026-69264のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-69264 补丁与修复 (2)

CVE-2026-69264 厂商安全公告 (1)

CVE-2026-69264 厂商页面 (1)

Same Patch Batch · FlowiseAI · 2026-08-04 · 22 CVEs total

CVE-2026-704779.5 CRITICALFlowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-704709.5 CRITICALFlowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-692549.4 CRITICALFlowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
CVE-2026-692599.4 CRITICALFlowise RCE via SQLite Record Manager Node
CVE-2026-692569.4 CRITICALFlowise: Remote Code Execution Vulnerability in CSVAgent
CVE-2026-704789.2 CRITICALFlowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables tok
CVE-2026-692559.2 CRITICALFlowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
CVE-2026-692519.0 CRITICALFlowise RCE via TypeORM DataSource
CVE-2026-692539.0 CRITICALFlowise Sandbox Escape to RCE
CVE-2026-692588.8 HIGHFlowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overr
CVE-2026-692638.7 HIGHFlowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable bloc
CVE-2026-692508.5 HIGHFlowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
CVE-2026-704738.3 HIGHFlowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wi
CVE-2026-704768.3 HIGHFlowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billin
CVE-2026-704747.6 HIGHFlowise: Cross-Workspace OAuth2 Credential Metadata Leak
CVE-2026-692577.6 HIGHFlowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
CVE-2026-692527.2 HIGHFlowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list a
CVE-2026-692627.1 HIGHFlowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentfl
CVE-2026-704717.1 HIGHFlowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
CVE-2026-704727.1 HIGHFlowise: Cross-workspace credential IDOR in openai-assistants-vector-store

Showing 20 of 22 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-69264へのコメント

まだコメントはありません


コメントを残す