HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Remote Code Execution via Prompt Injection in Flowise CSV Agent (CVE‑2026‑70477)

A newly disclosed vulnerability (CVE‑2026‑70477) in Flowise’s CSV Agent allows unauthenticated attackers to execute arbitrary code by injecting malicious prompts into LLM calls. The flaw scores 9.8 CVSS, indicating a critical risk for organizations that integrate Flowise into their AI pipelines. This underscores the need for robust input validation and continuous control assurance to meet audit expectations.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 zerodayinitiative.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution via Prompt Injection in Flowise CSV Agent (CVE‑2026‑70477)

What It Is — Flowise’s CSV Agent component contains a flaw that lets an attacker inject malicious text into an LLM prompt, leading to arbitrary code execution on the service account. No authentication or user interaction is required.

Exploitability — The vulnerability is publicly disclosed, has a CVSS 9.8 (Critical) score, and can be exploited remotely with a crafted CSV file. No proof‑of‑concept is needed beyond sending the malicious payload.

Affected Products — Flowise (all versions prior to the September 2026 patch) – specifically the CSV_Agents class used for CSV‑based data ingestion.

Why It Matters for Trust & Control Assurance

  • Highlights the need for input‑validation controls that span third‑party AI components, a control objective that satisfies many frameworks (e.g., NIST CSF, ISO 27001).
  • Demonstrates why continuous control mapping and evidence collection are essential to prove that vendor‑supplied code meets your organization’s security policies.
  • Provides a concrete example of how a missing sanitization step can break a defensible audit trail, prompting buyers to demand verifiable remediation evidence.

Recommended Actions

  1. Deploy Flowise’s September 2026 security update immediately.
  2. Review all CSV‑based ingestion pipelines for unsanitized LLM prompts; add strict sanitization or whitelist allowed tokens.
  3. Enable runtime monitoring and alerting for unexpected command execution in the service account context.
  4. Update your control‑mapping inventory to reflect the new input‑validation control and capture remediation evidence.

Source: Zero Day Initiative Advisory – ZDI‑26‑634 (CVE‑2026‑70477)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-634/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →