What is CVE-2026-70477?
CVE-2026-70477 is a prompt injection vulnerability in the Flowise platform. A specially crafted prompt sent to a chatflow using a CSV Agent node can cause the LLM to generate a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Python environment. Upgrading to version 3.1.3 or later is recommended.
Azərbaycanca: CVE-2026-70477 Flowise platformunda aşkar edilmiş prompt injection zəifliyidir. CSV Agent node istifadə edən chatflow-a göndərilən xüsusi sorğu, LLM-in blok siyahısı validatorunu keçərək qorunmayan Python mühitində işləyən zərərli skript yaratmasına səbəb ola bilər. 3.1.3 versiyasına qədər təsirli olan bu boşluğu aradan qaldırmaq üçün Flowise-ni yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which platform does CVE-2026-70477 affect?
It affects the Flowise platform, specifically chatflows that use a CSV Agent node.
What version should be upgraded to fix CVE-2026-70477?
Upgrading Flowise to version 3.1.3 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.