FlowiseAI / TrendAI Research
aidefend-sf0028
Flowise CSV Agent Prompt Injection to Host-Capable Pyodide
- Autonomous Agents
- System Compromise & RCE
An unauthenticated prompt sent to an affected CSV Agent chatflow can make the LLM emit obfuscated Python. Flowise 3.1.2 and earlier validate that output with a static regex blocklist, then execute accepted code through Pyodide without isolating it from host operating-system interfaces.
Mapped threat techniques
AML.T0051.000LLM Prompt Injection: DirectAML.T0107Exploitation for Defense EvasionAML.T0050Command and Scripting Interpreter