5 min read
Vulnerabilities CVE-2026-41264 in Flowise's CSVAgent node lets an attacker upload a crafted CSV file, inject a prompt that directs the LLM to generate malicious Python, and execute that code on the host with no authentication required. Metasploit module landed July 11, 2026.