THREAT OPS › Threat News › [GHSA] GHSA-5xvg-pmgg-3mxr (critical) — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
[GHSA] GHSA-5xvg-pmgg-3mxr (critical) — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-5xvg-pmgg-3mxr Severity: critical CVE: CVE-2026-70477
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
-- ABSTRACT -------------------------------------
Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: Flowise - Flowise
-- VULNERABILITY DETAILS ------------------------ * Version tested: 3.1.1 * Installer file: https:
MITRE ATT&CK techniques
- System PromptAML.T0069.002
Indicators of compromise
- CVE-2026-70477cve
Original source: https://github.com/advisories/GHSA-5xvg-pmgg-3mxr