What is CVE-2026-69256?
CVE-2026-69256 is a security vulnerability in Flowise, a drag-and-drop UI for custom LLM flows. The CSVAgent node allowed arbitrary Python code execution via pandas.read_pickle() despite a denylist for dangerous constructs. Users should upgrade to version 3.1.3.
Related CVEs
link basis: shared vendor: Flowise
FAQ2
Which node in Flowise can be exploited through CVE-2026-69256?
This vulnerability can be exploited through the CSVAgent node in Flowise.
What should users do to mitigate CVE-2026-69256?
Users should upgrade Flowise to version 3.1.3.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.