THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vmv7-4m6c-3cg5 (critical) — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

[GHSA] GHSA-vmv7-4m6c-3cg5 (critical) — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

medgithub_advisoriesPublished 2026-08-04

GHSA-vmv7-4m6c-3cg5 Severity: critical CVE: CVE-2026-69255

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

## UPDATE 2026-05-20: Full RCE as root VERIFIED

**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**

### Verified Exploit Chain

1. Python code injection via `base64_string = "${base64Str

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vmv7-4m6c-3cg5