THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70477 (CRITICAL 9.8) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in

[NVD] CVE-2026-70477 (CRITICAL 9.8) — Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in

lownvdPublished 2026-08-04

CVE-2026-70477 CVSS: 9.8 CRITICAL Published: 2026-08-04T20:16:54.473

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific f

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70477