THREAT OPS › Threat News › [GHSA] GHSA-vmv7-4m6c-3cg5 (critical) — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
[GHSA] GHSA-vmv7-4m6c-3cg5 (critical) — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
GHSA-vmv7-4m6c-3cg5 Severity: critical CVE: CVE-2026-69255
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
## UPDATE 2026-05-20: Full RCE as root VERIFIED
**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**
### Verified Exploit Chain
1. Python code injection via `base64_string = "${base64Str
MITRE ATT&CK techniques
- Reverse ShellAML.T0072
Indicators of compromise
- CVE-2026-69255cve
- CVE-2026-41264cve
- CVE-2026-41265cve
- CVE-2026-46442cve
Original source: https://github.com/advisories/GHSA-vmv7-4m6c-3cg5