CVE-2026-41264: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results fr...
Added to the CISA Known Exploited Vulnerabilities catalog on 23 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can lev...
Required action: Review and patch if applicable to your AI infrastructure.