HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution via Prompt Injection in Flowise CSV Agent (CVE‑2026‑70477)

A newly disclosed vulnerability (CVE‑2026‑70477) in Flowise’s CSV Agent allows unauthenticated attackers to execute arbitrary code by injecting malicious prompts into LLM calls. The flaw scores 9.8 CVSS, indicating a critical risk for organizations that integrate Flowise into their AI pipelines. This underscores the need for robust input validation and continuous control assurance to meet audit expectations.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 zerodayinitiative.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution via Prompt Injection in Flowise CSV Agent (CVE‑2026‑70477)

What It Is — Flowise’s CSV Agent component contains a flaw that lets an attacker inject malicious text into an LLM prompt, leading to arbitrary code execution on the service account. No authentication or user interaction is required.

Exploitability — The vulnerability is publicly disclosed, has a CVSS 9.8 (Critical) score, and can be exploited remotely with a crafted CSV file. No proof‑of‑concept is needed beyond sending the malicious payload.

Affected Products — Flowise (all versions prior to the September 2026 patch) – specifically the CSV_Agents class used for CSV‑based data ingestion.

Why It Matters for Trust & Control Assurance

  • Highlights the need for input‑validation controls that span third‑party AI components, a control objective that satisfies many frameworks (e.g., NIST CSF, ISO 27001).
  • Demonstrates why continuous control mapping and evidence collection are essential to prove that vendor‑supplied code meets your organization’s security policies.
  • Provides a concrete example of how a missing sanitization step can break a defensible audit trail, prompting buyers to demand verifiable remediation evidence.

Recommended Actions

  • Deploy Flowise’s September 2026 security update immediately.
  • Review all CSV‑based ingestion pipelines for unsanitized LLM prompts; add strict sanitization or whitelist allowed tokens.
  • Enable runtime monitoring and alerting for unexpected command execution in the service account context.
  • Update your control‑mapping inventory to reflect the new input‑validation control and capture remediation evidence.

Source: Zero Day Initiative Advisory – ZDI‑26‑634 (CVE‑2026‑70477)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-634/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →