A vulnerability, which was classified as very critical, has been found in FlowiseAI Flowise up to 3.1.2. Affected by this vulnerability is the function
validatePythonCodeForDataFrame of the file packages/components/nodes/agents/CSVAgent/CSVAgent.ts of the component CSVAgent. Performing a manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-69255. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.