← Back to feed
advisories Zero Day Initiative

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

Zero Day Initiative

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vul...

T1190 1 IOC
Read the full story Zero Day Initiative →

Related Coverage

advisories ISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd) SANS ISC · Sep 23 advisories Macfinger ClickFix campaign, (Tue, Sep 22nd) SANS ISC · Sep 23 advisories The Truth about GET and HTTP Standards, (Tue, Sep 22nd) SANS ISC · Sep 22