Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-41264: How a Regex Let Prompts Run Code in Flowise

import pandas as np , os as pandas pandas . system ( " xcalc " ) Those two lines are the whole bypass in CVE-2026-41264 , a CVSS 9.8 bug in Flowise , the open source drag-and-drop builder for LLM apps. Flowise's CSV Agent asked a model to write pandas code, checked the code with a regex, and ran it on the server. The regex was meant to stop any import other than pandas or numpy. It looked at the…

CVE-2026-41264 is a critical vulnerability affecting Flowise, an open-source drag-and-drop builder for Language Learning Model (LLM) applications. The flaw allows arbitrary code execution through malformed prompts, with a CVSS score of 9.8. The issue stems from a regex in Flowise's CSV Agent that only checks the first module name after `import`, allowing an attacker to bypass the security check by aliasing the `os` module as `pandas`.

This bypass enables the execution of malicious code, undermining the intended restrictions on imports such as `exec`, `eval`, `open`, `os`, or `subprocess`.

The vulnerability was reported by Trend Micro's Zero Day Initiative (ZDI) and fixed in Flowise 3.1.3. The fix includes stricter regex rules, removing the CSV Agent and its associated validator, and implementing additional security checks. The ZDI proof of concept demonstrated that an unauthenticated attacker could exploit the vulnerability using prompt injection techniques, targeting models like Llama 3.2 running in Ollama.

The vulnerability also highlights a secondary issue within Pyodide, a WebAssembly-based Python interpreter, which could allow child_process execution in the Flowise container, potentially leading to root access. This oversight underscored the limitations of WebAssembly in providing complete isolation, despite its memory access restrictions.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Why search-and-replace is the wrong way to fix a trailing comma in JSON

A single comma can make a whole JSON file unusable: { "name" : "ada" , "roles" : [ "admin" , "ops" ,], } # Python json.decoder.JSONDecodeError: Expecting value: line 3 column 28 (char 46) # Node /…

  • Trailing commas in JSON cause parsing errors
  • Simple re.sub fix corrupts string values
  • Proper solution tracks string state and escapes

More from Monday 5 October →