chiprook
← Security
SecurityOctober 5, 2026, 21:21

CVE-2026-41264: A Regex Let Prompts Run Code in Flowise

Flowise, the open source drag-and-drop builder for LLM apps, had a CVSS 9.8 flaw: its CSV Agent asked a model to write pandas code, checked it with a regex, and ran it on the server. An alias os as pandas bypass gave RCE; the 3.1.0 fix failed and the feature was removed in June.

CVE-2026-41264: A Regex Let Prompts Run Code in Flowise
#Flowise
Read next
Security

Unsloth Studio flaw let malicious AI models run Python code on inspection

Security

Leaked GitLab issue email address lets anyone push code and run CI jobs as you

Security

cPanel flaw lets a hosting account run code as root and take over the server

Security

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store