A vulnerability, which was classified as critical, was found in FlowiseAI Flowise up to 3.1.2. Affected by this issue is the function pandas.read_pickle of the file flowise-components/nodes/agents/CSVAgent/CSVAgent.ts of the component CSVAgent. Executing a manipulation of the argument customReadCSVFunc can lead to deserialization.

This vulnerability is registered as CVE-2026-69256. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.