THREAT OPS › Threat News › [NVD] CVE-2026-70477 (CRITICAL 9.8) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in
[NVD] CVE-2026-70477 (CRITICAL 9.8) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in
CVE-2026-70477 CVSS: 9.8 CRITICAL Published: 2026-08-04T20:16:54.473
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific f
Indicators of compromise
- CVE-2026-70477cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70477